ROBERT KRUCZEK
← Back to home

CVE-2025-50056

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS v4.0: 5.1 (MEDIUM) Published: July 18, 2025 View on NVD →

Description

A reflected XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 28 Joomla was discovered. The issue allows remote attackers to inject arbitrary web script or HTML via the crafted parameter.

Affected Products

Vendor Product Versions Affected
rsjoomla.com RSMail! component for Joomla 1.19.20-1.22.28 (affected)

CVSS Score & Vector

Base Score: 5.1 (MEDIUM)
Vector (v4.0):
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Credits / Discoverer

  • Kamil Szczurowski
  • Robert Kruczek

References & Advisories