Joomla 插件 - joomshaper.com - SP Property < 4.1.4 中前端视图和管理员列表表格中未转义输出导致的未认证存储型跨站脚本攻击(XSS) 在 SP Property 4.1.4 之前的版本中,多个模板文件(涵盖前端视图和管理员列表表格)将属性值和文本值直接渲染到 HTML 中,而未进行上下文相关的转义处理,从而导致未认证的攻击者可通过存储型 XSS 漏洞在用户浏览器中执行任意 JavaScript 代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| joomshaper.com | SP Property extension for Joomla | 1.0.0-4.1.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78082 | 9.3 CRITICAL | Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and M |
| CVE-2026-78083 | 7.1 HIGH | Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking an |
| CVE-2026-78303 | 6.9 MEDIUM | Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in B |
| CVE-2026-78084 | 6.9 MEDIUM | Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in |
| CVE-2026-78085 | 6.9 MEDIUM | Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Prope |
No comments yet