Joomla · Jomres · CVE-2013-3931
Name of the Vulnerable Software and Affected Versions:
Jomres (com jomres) versions prior to 7.3.1 for Joomla!
Description:
A cross-site scripting (XSS) issue allows remote authenticated users with the "Business Manager" permission to inject arbitrary web script or HTML via the `property name` parameter, related to editing property details.
Recommendations:
For versions prior to 7.3.1, update to version 7.3.1 or later to resolve the issue.
As a temporary workaround, consider restricting access to the `property name` parameter when editing property details until the update is applied.