Impact
Raw exception messages are returned by the Quix Page Builder Pro AJAX handler, revealing server and configuration details that could aid an attacker in mapping the environment or tailoring exploits. The vulnerability is a classic information disclosure flaw, potentially exposing sensitive data to unauthenticated users. No evidence of integrity or availability impact is noted; the primary concern is confidentiality.
Affected Systems
The vulnerability affects the Joomla extension Quix Page Builder Pro from themexpert.com, specifically versions earlier than 6.2.1. Administrators using any of these versions on their Joomla sites are at risk until the component is updated.
Risk and Exploitability
With a CVSS score of 6.9, the flaw represents moderate risk. The EPSS score of < 1% indicates a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation to date. The likely attack vector is a remote web request to the vulnerable AJAX endpoint, where raw exception messages are returned and could be leveraged by an attacker to deduce application structure or system configuration without requiring elevated privileges.
OpenCVE Enrichment