Cross-site scripting (XSS) vulnerability in the Marketplace (com_marketplace) component 1.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the catid parameter in a show_category action to index.php.Referenceshttp://www.packetstormsecurity.com/1001-exploits/joomlamarketplace-xss.txthttps://exchange.xforce.ibmcloud.com/vulnerabilities/55662http://www.securityfocus.com/bid/37819