Impact
The Modals extension for Joomla incorrectly accepts URLs that use executable browser schemes such as javascript:, data:, or other non‑HTTP a URL, the code is rendered both as a link and loaded in an iframe, causing the injected JavaScript to execute in any visitor’s browser. Because the payload is stored in the modal configuration, it persists until the modal is edited or deleted, providing a persistent stored XSS vulnerability.
Affected Systems
This vulnerability affects installations of the regularlabs.com Modals extension, both Free and Pro editions, for Joomla running any version earlier than 17.0.0. Versions 17.0.0 and later are not affected.
Risk and Exploitability
The vulnerability is scored 7.5 on the CVSS v3.1 scale and has an EPSS score of <1%, indicating a low probability of exploitation yet a high severity. The vulnerability. Based on the description, it is inferred that the likely attack path involves a content editor or administrator creating or editing a modal and inserting an executable URL scheme. The stored payload causes JavaScript to execute in the browsers of any site visitor who opens the modal, which can lead to arbitrary code execution in the front‑end. In the absence of a patch, the risk to sites that rely on unpatched Modals remains significant.
OpenCVE Enrichment