Impact
The Cache Cleaner Pro extension allows administrators to set custom purge and log paths. The extension does not enforce proper validation of these paths, which is classified as CWE‑22. This flaw enables an attacker to use directory traversal sequences to escape the Joomla webroot, potentially reading arbitrary files such as configuration files or credential stores. The vulnerability carries a CVSS base score of 6.5, indicating medium severity.
Affected Systems
All Joomla sites that include the Cache Cleaner Pro extension from regularlabs.com are potentially affected. The vulnerability report does not specify a particular version, so any currently installed or legacy version may contain the flaw until a vendor patch is applied.
Risk and Exploitability
The EPSS score is reported as less than 1%, indicating a very low exploitation probability at present, and the flaw is not listed in CISA's KEV catalog. It is inferred that an attacker would need administrative access to the Joomla backend to manipulate the extension's configuration settings, although an unauthenticated attacker might influence the extension if it is exposed via the public interface. Despite the low exploitation probability, the medium‑severity rating and the potential for confidential file disclosure warrant timely remediation.
OpenCVE Enrichment