ROBERT KRUCZEK
← Back to home

CVE-2025-50058

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS v4.0: 5.1 (MEDIUM) Published: July 18, 2025 View on NVD →

Description

A stored XSS vulnerability in the RSDirectory! component 1.0.0-2.2.8 Joomla was discovered. The issue allows remote authenticated attackers to inject arbitrary web script or HTML via the review reply component.

Affected Products

Vendor Product Versions Affected
rsjoomla.com RSDirectory! component for Joomla 1.0.0-2.2.8 (affected)

CVSS Score & Vector

Base Score: 5.1 (MEDIUM)
Vector (v4.0):
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Credits / Discoverer

  • Kamil Szczurowski
  • Robert Kruczek

References & Advisories