Skip to main content

CVE-2025-50058: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in rsjoomla.com RSDirectory! component for Joomla

Medium
VulnerabilityCVE-2025-50058cvecve-2025-50058cwe-79
Published: Fri Jul 18 2025 (07/18/2025, 09:51:29 UTC)
Source: CVE Database V5
Vendor/Project: rsjoomla.com
Product: RSDirectory! component for Joomla

Description

A stored XSS vulnerability in the RSDirectory! component 1.0.0-2.2.8 Joomla was discovered. The issue allows remote authenticated attackers to inject arbitrary web script or HTML via the review reply component.

Technical Details

Data Version
5.1
Assigner Short Name
Joomla
Date Reserved
2025-06-11T19:08:08.079Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 687a1b67a83201eaacf1f470

Added to database: 7/18/2025, 10:01:11 AM

Last updated: 7/18/2025, 10:01:11 AM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats