CVE-2023-54364

Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating GET parameters in the product filter endpoint. Attackers can craft malicious URLs containing XSS payloads in the from_option, from_ctrl, from_task, or from_itemid parameters to steal session tokens or login credentials when victims visit the link.
Configurations

No configuration.

History

09 Apr 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-09 21:16

Updated : 2026-04-15 15:00


NVD link : CVE-2023-54364

Mitre link : CVE-2023-54364

CVE.ORG link : CVE-2023-54364


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')