Impact
The Modals Pro extension for Joomla builds gallery URLs without proper sanitisation, allowing an attacker to craft requests that reveal directory listings beyond the intended scope. This flaw is a classic path traversal weakness, identified as CWE‑22, and the principal impact is information disclosure; there is no evidence of remote code execution or privilege escalation.
Affected Systems
The vulnerability is limited to the Modals Pro extension distributed by regularlabs.com, which integrates with the Joomla content management system. No specific version numbers are listed, so any installation containing the affected path handling logic is potentially vulnerable. Administrators should verify whether their Joomla site uses this extension and review the vendor’s release notes for a fix.
Risk and Exploitability
The CVSS score of 6.5 classifies the issue as moderate severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation, and the flaw is not present in the CISA KEV catalog. The attack vector is most likely web‑based, involving unauthenticated users sending specially crafted gallery URLs. Because the vulnerability does not require elevated privileges or additional pre‑conditions, the potential damage is confined to disclosure of filesystem structure, but remediation is still advised to prevent future exploitation.
OpenCVE Enrichment