CVE-2025-27444: Extension - rsjoomla.com - A reflected XSS vulnerability RSform!Pro component 3.0.0 - 3.3.13 for Joomla
A reflected XSS vulnerability in RSform!Pro component 3.0.0 - 3.3.13 for Joomla was discovered. The issue arises from the improper handling of the filter[dateFrom] GET parameter, which is reflected unescaped in the administrative backend interface. This allows an authenticated attacker with admin or editor privileges to inject arbitrary JavaScript code by crafting a malicious URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27444?
CVE-2025-27444 is a reflected XSS vulnerability that poses a medium risk, particularly in the administrative backend of Joomla.
How does CVE-2025-27444 affect RSform!Pro?
CVE-2025-27444 affects RSform!Pro versions 3.0.0 to 3.3.13 by allowing unauthorized script execution through an unescaped GET parameter.
How do I fix CVE-2025-27444?
To fix CVE-2025-27444, update RSform!Pro to the latest version that addresses this reflected XSS vulnerability.
Who is vulnerable to CVE-2025-27444?
Any user running RSform!Pro versions 3.0.0 to 3.3.13 on a Joomla site is vulnerable to CVE-2025-27444.
What type of attack can CVE-2025-27444 enable?
CVE-2025-27444 can enable an authenticated attacker to execute arbitrary JavaScript code in the context of the affected Joomla administrative backend.