Stored XSS in RSDirectory Component for Joomla by RSJoomla
CVE-2025-50058

5.1MEDIUM

Key Information:

Vendor
CVE Published:
18 July 2025

What is CVE-2025-50058?

A stored Cross-Site Scripting (XSS) vulnerability was identified in the RSDirectory! component for Joomla, which allows remote authenticated attackers to inject arbitrary web scripts or HTML through the review reply feature. This can potentially lead to data theft, session hijacking, and other malicious activities, posing a significant threat to users of the affected versions.

Affected Version(s)

RSDirectory! component for Joomla 1.0.0-2.2.8

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kamil Szczurowski
Robert Kruczek
.
CVE-2025-50058 : Stored XSS in RSDirectory Component for Joomla by RSJoomla