PT-2026-31730 · Joomla · Solidres

Cracker

·

Published

2026-04-09

·

Updated

2026-04-09

·

CVE-2023-54363

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Joomla Solidres version 2.13.3
Description Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts. Attackers can manipulate multiple GET parameters, including show, reviews, type id, distance, facilities, categories, prices, location, and Itemid, to craft malicious URLs containing JavaScript payloads. When victims visit these crafted links, attackers can potentially steal session tokens, login credentials, or manipulate site content.
Recommendations Update Joomla Solidres to a newer version that contains a fix for this vulnerability.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-54363

Affected Products

Solidres