JoomShopping (com_jshopping) 3.5.0 to 5.9.2 - Unauthenticated Reflected XSS
JoomShopping up to and including 5.9.2 contains a reflected cross-site scripting vulnerability in the product frontend controller. An attacker who gets a logged-in user or administrator to follow a crafted link can execute script in that user session. Update to 5.9.3 or later. This rule starts at 3.5.0 so it does not match the OSMap and Xmap JoomShopping companion plugins, which report their own 2.0.x-3.2.1 versions under the same element; the oldest real JoomShopping install seen in the wild is 3.12.0.
Affected versions: ≥ 3.5.0 and ≤ 5.9.2
Full advisory: www.joomshopping.com