Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating multiple GET parameters including show, reviews, type_id, distance, facilities, categories, prices, location, and Itemid. Attackers can craft malicious URLs containing JavaScript payloads in these parameters to steal session tokens, login credentials, or manipulate site content when victims visit the crafted links.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 09 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating multiple GET parameters including show, reviews, type_id, distance, facilities, categories, prices, location, and Itemid. Attackers can craft malicious URLs containing JavaScript payloads in these parameters to steal session tokens, login credentials, or manipulate site content when victims visit the crafted links. | |
| Title | Joomla Solidres 2.13.3 Reflected XSS via Multiple Parameters | |
| First Time appeared |
Solidres
Solidres solidres |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:solidres:solidres:2.13.3:*:*:*:*:*:*:* | |
| Vendors & Products |
Solidres
Solidres solidres |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-04-09T20:54:52.838Z
Updated: 2026-04-10T15:55:28.694Z
Reserved: 2026-04-09T20:42:16.616Z
Link: CVE-2023-54363
Updated: 2026-04-10T15:53:31.709Z
Status : Received
Published: 2026-04-09T21:16:05.907
Modified: 2026-04-09T21:16:05.907
Link: CVE-2023-54363
No data.