peter bassill · operator
$ cve CVE-2010-4949 JSON

CVE-2010-4949 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 1.7% (pctl 76)

Patch early

A public exploit exists.

Description

Cross-site scripting (XSS) vulnerability in the (1) FreiChat component before 2.1.2 for Joomla! and the (2) FreiChatPure component before 1.2.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML by entering it in an unspecified window.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS1.69% — more likely to be exploited than 76% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2011-10-09
Last modified2026-06-16

Affected (3)

VendorProduct
evnixfreichat
evnixfreichatpure
joomlajoomla\!

Public exploits

SourceTitleDate
exploit-dbJoomla! Component FreiChat 1.0/2.x - HTML Injection2010-07-26

References

→ the Explorer  ·  watch your stack  ·  NVD