Impact
An unauthenticated attacker can trigger the Gallery element of the Zoo extension in Joomla to retrieve an arbitrary directory listing. This permissive behavior reveals file names and paths, potentially exposing confidential or configuration files. The flaw is a directory traversal and reading weakness classified as CWE-22.
Affected Systems
The vulnerability affects the Zoo extension for Joomla, provided by yootheme.com, in all releases prior to version 4.1.66. No specific sub‑versions are listed; any installed Zoo extension version below 4.1.66 is considered exposed.
Risk and Exploitability
The CVSS base score is 6.9, indicating medium severity. No EPSS data is available, and the issue is not listed in CISA's KEV catalog. Exploitation requires only an unauthenticated web request to the targeted Joomla site, making the attack likely when the site is publicly reachable. The impact is limited to information disclosure but may aid subsequent attacks by revealing sensitive file structures.
OpenCVE Enrichment