Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-15120. PoCs published by h3llraiser.
AI-analyzed exploit summary The repository provides a functional proof-of-concept for CVE-2019-15120, demonstrating a stored XSS vulnerability in the Kunena extension for Joomla! via maliciously crafted BBCode. The exploit leverages the `[spoiler]` tag to inject arbitrary JavaScript, which can lead to RCE under certain conditions.
Description
The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.
Exploits (1)
The repository provides a functional proof-of-concept for CVE-2019-15120, demonstrating a stored XSS vulnerability in the Kunena extension for Joomla! via maliciously crafted BBCode. The exploit leverages the `[spoiler]` tag to inject arbitrary JavaScript, which can lead to RCE under certain conditions.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N