CVE-2020-5182: Medium severity CMSJunkie J-businessdirectory Joomla\! vulnerability

Published Feb 3, 2020
·
Updated

The J-BusinessDirectory extension before 5.2.9 for Joomla! allows Reverse Tabnabbing. In some configurations, the link to the business website can be entered by any user. If it doesn't contain rel="noopener" (or similar attributes such as noreferrer), the tabnabbing may occur. To reproduce the bug, create a business with a website link that contains JavaScript to exploit the window.opener property (for example, by setting window.opener.location).

Affected Software

1 affected component
CMSJunkie J-businessdirectory Joomla\!<5.2.9

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade J-BusinessDirectory extension to a version that resolves this vulnerability.

    Fixed in 5.2.9
  2. Configuration

    Ensure outbound links generated from the business website field include rel="noopener" (or similar like "noreferrer") to prevent reverse tabnabbing via window.opener.

    J-BusinessDirectory extension (Joomla!) business website link handling (rel="noopener"/"noreferrer" on outbound links) = Add rel="noopener" (or similar, e.g., "noreferrer") to outbound anchor tags that reference the business website
  3. Configuration

    In configurations where the business website link can be entered by any user, restrict this ability to trusted users to prevent injection of JavaScript into the window.opener context.

    J-BusinessDirectory extension (Joomla!) permission to enter business website link = Restrict to trusted users only

Event History

Feb 3, 2020
CVE Published
via MITRE·04:52 PM
Data Sourced
via MITRE·04:52 PM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2020-5182?

The severity of CVE-2020-5182 is considered low, as it primarily involves potential user experience issues rather than direct threats.

2

How do I fix CVE-2020-5182?

To fix CVE-2020-5182, update the J-BusinessDirectory extension to version 5.2.9 or higher.

3

What is Reverse Tabnabbing in CVE-2020-5182?

Reverse Tabnabbing refers to the technique where a newly opened tab can change the location of its originating tab, risking user information.

4

Who is affected by CVE-2020-5182?

Users of the J-BusinessDirectory extension for Joomla! version prior to 5.2.9 are affected by CVE-2020-5182.

5

Is CVE-2020-5182 an urgent vulnerability to address?

While CVE-2020-5182 poses a risk, it is not deemed urgent due to its nature, but it is advisable to apply the fix to ensure best practices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203