Cross-Site Scripting Vulnerability in JChatSocial Component for Joomla!
CVE-2014-3863
Currently unrated
What is CVE-2014-3863?
The JChatSocial component for Joomla! prior to version 2.3 contains a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML. This is achieved by manipulating the filename parameter in a file upload within an active JChat chat window, potentially leading to unauthorized actions or data exposure for users interacting with the chat interface.
