CVE-2025-50058
Description
A stored XSS vulnerability in the RSDirectory! component 1.0.0-2.2.8 Joomla was discovered. The issue allows remote authenticated attackers to inject arbitrary web script or HTML via the review reply component.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS in RSDirectory! Joomla component 1.0.0-2.2.8 allows authenticated attackers to inject arbitrary web script via review replies.
A stored cross-site scripting (XSS) vulnerability exists in the RSDirectory! component for Joomla, affecting versions 1.0.0 through 2.2.8. The issue resides in the review reply feature, where user-supplied input is not properly sanitized before being stored. This allows an attacker to inject arbitrary web script or HTML that will be executed in the context of other users viewing the review [1].
The vulnerability can be exploited by remote authenticated users who have the ability to post review replies. No elevated privileges beyond standard user authentication are required to inject malicious content. The attack vector is network-based, and exploitation does not require any special user interaction beyond the victim viewing the compromised review [1].
Successful exploitation enables the attacker to execute arbitrary JavaScript in the browser of any user who accesses the affected review reply. This can lead to session hijacking, defacement, phishing attacks, or further compromise of the Joomla site. Given that social engineering is often required to lure victims to the malicious content, the severity is assessed as Medium [1].
The vendor, RSJoomla, has addressed this vulnerability in version 2.3.4 of RSDirectory!, as indicated by their changelog. Users are strongly advised to upgrade to the latest version to mitigate the risk. No workaround is available if the component cannot be updated [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2>=1.0.0,<=2.2.8+ 1 more
- (no CPE)range: >=1.0.0,<=2.2.8
- (no CPE)range: <=2.2.8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- rsjoomla.comnvd
News mentions
0No linked articles in our index yet.