Reflected Cross-Site Scripting in Joomla JLex Review by Joomla
CVE-2023-54360
Key Information:
- Vendor
Jlexart
- Status
- Vendor
- CVE Published:
- 9 April 2026
Badges
What is CVE-2023-54360?
Joomla JLex Review 6.0.1 has been found to possess a reflected cross-site scripting vulnerability, which allows attackers to exploit the review_id URL parameter. By constructing malicious links that contain specially crafted JavaScript payloads, attackers can execute scripts in the browsers of unsuspecting users. This vulnerability poses risks of session hijacking and credential theft, making it imperative for users to ensure their installations are updated to prevent such attacks.
Affected Version(s)
Joomla JLex Review 6.0.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
