GHSA-hmp2-w6r9-h3f2Medium

Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5...

Published
September 28, 2026
Last Modified
September 28, 2026

🔗 CVE IDs covered (1)

📋 Description

Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8 - The public vehicle-detail page (task=view) echoes the title request parameter directly into a double-quoted HTML attribute with no output encoding of any kind. A double-quote character in the parameter closes the attribute, allowing arbitrary markup, including a tag, to be injected into the page.

🔗 References (3)