First published: Sun Mar 09 2025(Updated: )
A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla. It has been classified as problematic. Affected is an unknown function of the file /extensions/realestate/index.php/properties/list/list-with-sidebar/realties. The manipulation of the argument Itemid/jp_yearbuilt leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
JoomlaUX JUX Real Estate |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2127 has been classified as problematic, indicating that it poses a notable risk to affected systems.
To fix CVE-2025-2127, you should update the JoomlaUX JUX Real Estate extension to the latest version provided by the vendor.
The vulnerable file in CVE-2025-2127 is /extensions/realestate/index.php/properties/list/list-with-sidebar/realties.
CVE-2025-2127 affects an unknown function, which manipulates the argument Itemid/jp_yearbuilt.
CVE-2025-2127 impacts JoomlaUX JUX Real Estate version 3.4.0.