Impact
The vulnerability resides in the Filesystem source within YOOtheme Pro, where the path filter is susceptible to glob‑based pattern attacks. Authorized users can use this flaw to read files arbitrarily, potentially exposing sensitive configuration data, credentials, or other confidential information. This results in a confidentiality breach under the documented CWE‑22 classification.
Affected Systems
The flaw affects users of the YOOtheme Pro extension for Joomla published by yootheme.com. All versions of the extension in the 2.3.0 through 5.0.40 range are impacted.
Risk and Exploitability
The CVSS score of 7.0 indicates a high severity exploit. The EPSS score is not available, but the vulnerability requires an authenticated user with privilege to read files, which limits immediate public exploitation risk. The KEV status is not listed, suggesting no known active exploitation campaigns. Nonetheless, the existence of an arbitrary file read flaw warrants prompt remediation to protect sensitive assets.
OpenCVE Enrichment