Joomla HikaShop 4.7.4 Reflected XSS via Product Filter
Vulnerability Description
Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating GET parameters in the product filter endpoint. Attackers can craft malicious URLs containing XSS payloads in the from_option, from_ctrl, from_task, or from_itemid parameters to steal session tokens or login credentials when victims visit the link.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-54364
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- CraCkEr
Affected Vendor
Hikashop
View all reports →