Reflected XSS and XML Injection in J-BusinessDirectory by Cmsjunkie
CVE-2026-75955
5.1MEDIUM
What is CVE-2026-75955?
A security vulnerability has been identified in the J-BusinessDirectory extension for Joomla, where unsanitized data can be reflected in an XML attribute. Specifically, the 'companyName' parameter from user requests is not properly escaped, leading to potential reflected cross-site scripting (XSS) attacks and XML injection. Attackers could exploit this flaw to manipulate the behavior of web applications or execute arbitrary scripts in the context of the user's session, thereby compromising sensitive information and system integrity.
Affected Version(s)
J-BusinessDirectory extension for Joomla 1.0.0-6.2.2
