PT-2026-31727 · Unknown · Joomla Jlex Review

Cracker

·

Published

2026-04-09

·

Updated

2026-04-09

·

CVE-2023-54360

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Joomla JLex Review version 6.0.1
Description A reflected cross-site scripting issue exists that allows attackers to inject malicious scripts by manipulating the review id URL parameter. Attackers can craft malicious links containing JavaScript payloads that execute in victims' browsers when clicked, potentially enabling session hijacking or credential theft.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, sanitize the review id parameter to prevent the injection of malicious scripts.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-54360

Affected Products

Joomla Jlex Review