Impact
Stored condition values in the Regular Labs extension suite can contain arbitrary HTML or JavaScript that is rendered inside administrator summary pages. The vulnerability is a stored cross‑site scripting (XSS) flaw. The description does not directly state the exploitation path beyond rendering stored content, so the exact impact is limited to the execution of the injected script. Based on the nature of XSS, it is inferred that a successful exploit could run code in the context of a logged‑in administrator, which might compromise session integrity or allow the attacker to perform unauthorized actions.
Affected Systems
Joomla extensions from Regular Labs, including the Advanced Module Manager, Conditional Content, Content Templater Pro, and ReReplacer Pro. Versions affected are not specified in the current data.
Risk and Exploitability
The EPSS score is below 1 %, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 4.8 classifies it as medium severity. The likely attack vector is an authenticated administrator who can create or edit condition values, as the flaw resides in data that is displayed in administrative summaries. Successful exploitation would require an attacker to have access to the condition editing interface and to inject malicious content. The typical consequences of a stored XSS flaw, such as session hijacking or data theft, are inferred from common XSS attack patterns and are not explicitly detailed in the vendor’s description.
OpenCVE Enrichment