MEDIUM
Thethinkery
CVE published 2026-04-09
CVE-2023-54361
CVE-2023-54361 is a reflected cross-site scripting vulnerability in Joomla iProperty Real Estate 4.1.1. Attackers can inject malicious scripts by manipulating the filter_keyword parameter in the all-properties-with-map endpoint. This vulnerability allows attackers to execute arbitrary code in victim browsers and steal session tokens or credentials. Defenders should prioritize verifying exposure of the fil [truncated]