PT-2026-31729 · Joomla · Virtuemart

Cracker

·

Published

2026-04-09

·

Updated

2026-04-09

·

CVE-2023-54362

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Joomla VirtueMart Shopping-Cart version 4.0.12
Description A reflected cross-site scripting issue exists that allows attackers to inject malicious scripts by manipulating the keyword parameter. Attackers can craft malicious URLs containing script payloads in the keyword parameter of the product-variants endpoint to execute arbitrary JavaScript in victim browsers and potentially steal session tokens or credentials.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-54362

Affected Products

Virtuemart