Reflected Cross-Site Scripting Vulnerability in Joomla VirtueMart Shopping-Cart
CVE-2023-54362
Key Information:
- Vendor
Virtuemart
- Status
- Vendor
- CVE Published:
- 9 April 2026
Badges
What is CVE-2023-54362?
Joomla VirtueMart Shopping-Cart version 4.0.12 is susceptible to a reflected cross-site scripting flaw. The vulnerability arises when attackers manipulate the 'keyword' parameter within the product-variants endpoint to embed malicious JavaScript code. By crafting deceptive URLs, they can execute arbitrary scripts in the browser sessions of unsuspecting users. This exploitation poses serious security risks, enabling unauthorized access to session tokens and credentials.
Affected Version(s)
Cart 4.0.12
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
