CyberRota Analysis
AI-GeneratedThe Joomla Extension from yootheme.com is vulnerable to unauthenticated stored cross-site scripting (XSS) due to inadequate escaping of user-controlled input in comments and field elements in versions prior to 4.1.66. This vulnerability allows attackers to inject malicious scripts that can be executed in the context of other users, potentially compromising their data and session integrity. Organizations using this extension should prioritize patching to mitigate the risk of exploitation.
Original NVD Description
Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied input in comments and user supplied field elements weren't escaped, leading to a stored XSS vector.