CVE-2023-54364 PUBLISHED

Joomla HikaShop 4.7.4 Reflected XSS via Product Filter

Assigner: VulnCheck
Reserved: 09.04.2026 Published: 09.04.2026 Updated: 09.04.2026

Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating GET parameters in the product filter endpoint. Attackers can craft malicious URLs containing XSS payloads in the from_option, from_ctrl, from_task, or from_itemid parameters to steal session tokens or login credentials when victims visit the link.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Score: 5.1

Product Status

Vendor Hikashop
Product Joomla HikaShop
Versions
  • Version 4.7.4 is affected

Credits

  • CraCkEr finder

References

Problem Types

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE