Cross-Site Scripting Vulnerability in Jomres Component for Joomla!
CVE-2013-3931

5.4MEDIUM

Key Information:

Vendor

Jomres

Vendor
CVE Published:
2 January 2020

What is CVE-2013-3931?

The Jomres component for Joomla! has a Cross-Site Scripting (XSS) vulnerability that permits remote authenticated users with the 'Business Manager' permission to inject arbitrary web scripts or HTML. This flaw can be exploited through the 'property_name' parameter while editing property details, presenting opportunities for attackers to manipulate web pages and execute unauthorized code.

Affected Version(s)

Jomres component for Joomla! before 7.3.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.