Unrated severityNVD Advisory· Published Dec 14, 2011· Updated Apr 29, 2026
CVE-2011-4809
CVE-2011-4809
Description
Multiple cross-site scripting (XSS) vulnerabilities in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) language[], (2) university[], (3) persent[], (4) company_name[], (5) designation[], (6) music[], (7) books[], (8) movies[], (9) games[], (10) syp[], (11) ft[], and (12) fa[] parameters in a save task for a profile to index.php. NOTE: some of these details are obtained from third party information.
Affected products
1- cpe:2.3:a:joomlaextensions:com_hmcommunity:*:*:*:*:*:*:*:*Range: <=1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.exploit-db.com/exploits/18050nvdExploit
- secunia.com/advisories/46656nvdVendor Advisory
- joomlaextensions.co.in/index.phpnvd
- www.osvdb.org/76726nvd
News mentions
0No linked articles in our index yet.