Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16847 | A reflected XSS vulnerability in RSform!Pro component 3.0.0 - 3.3.13 for Joomla was discovered. The issue arises from the improper handling of the filter[dateFrom] GET parameter, which is reflected unescaped in the administrative backend interface. This allows an authenticated attacker with admin or editor privileges to inject arbitrary JavaScript code by crafting a malicious URL. |
| Link | Providers |
|---|---|
| https://rsjoomla.com/ |
|
Mon, 09 Jun 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rsjoomla
Rsjoomla rsform\!pro |
|
| CPEs | cpe:2.3:a:rsjoomla:rsform\!pro:*:*:*:*:*:joomla\!:*:* | |
| Vendors & Products |
Rsjoomla
Rsjoomla rsform\!pro |
Wed, 04 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 04 Jun 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A reflected XSS vulnerability in RSform!Pro component 3.0.0 - 3.3.13 for Joomla was discovered. The issue arises from the improper handling of the filter[dateFrom] GET parameter, which is reflected unescaped in the administrative backend interface. This allows an authenticated attacker with admin or editor privileges to inject arbitrary JavaScript code by crafting a malicious URL. | |
| Title | Extension - rsjoomla.com - A reflected XSS vulnerability RSform!Pro component 3.0.0 - 3.3.13 for Joomla | |
| Weaknesses | CWE-79 | |
| References |
|
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2025-06-05T13:20:53.740Z
Reserved: 2025-02-25T21:22:02.367Z
Link: CVE-2025-27444
Updated: 2025-06-04T13:43:24.718Z
Status : Analyzed
Published: 2025-06-04T08:15:21.613
Modified: 2025-06-09T15:04:33.780
Link: CVE-2025-27444
No data.
OpenCVE Enrichment
No data.
EUVD