Impact
The vulnerability is an incorrect access check within Joomla! CMS’s com_modules component that permits any visitor to view a list of installed modules on the site’s front‑end. This disclosure reveals module configuration details, allowing an attacker to gain insight into the site’s structure and potentially identify other weaknesses. The flaw is categorized as CWE‑284, and it provides informational disclosure rather than direct code execution or privilege escalation.
Affected Systems
The affected product is Joomla! CMS from Joomla! Project. No specific version information is provided, suggesting the issue applies to all pre‑patch releases that include the com_modules component. Any Joomla! installation that has not applied the official fix is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. The EPSS score of <1% suggests a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog, so there are no known widespread attacks. The attack vector is inferred to be the web front‑end, as an unauthenticated request can trigger the disclosure. An attacker with no special privileges could enumerate modules simply by browsing the site, which might aid other attacks.
OpenCVE Enrichment