CVE-2020-5182
The J-BusinessDirectory extension before 5.2.9 for Joomla!
MEDIUM
j-businessdirectory
Description
The J-BusinessDirectory extension before 5.2.9 for Joomla! allows Reverse Tabnabbing. In some configurations, the link to the business website can be entered by any user. If it doesn't contain rel="noopener" (or similar attributes such as noreferrer), the tabnabbing may occur. To reproduce the bug, create a business with a website link that contains JavaScript to exploit the window.opener property (for example, by setting window.opener.location).
Sévérité
6.5
Moyenne · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | MEDIUM | 6.5 (v3.1) |
Produit et versions
- Produit
- j-businessdirectory
- Corrigée dans
- 5.2.9
- Publiée
- 03/02/2020
- Modifiée
- 17/06/2026
- CWE
- CWE-269
Versions concernées
- j-businessdirectory — jusqu'à 5.2.9 (exclue)
Sources
- NVD CVE-2020-5182 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:34 UTC