Impact
The Tabs & Accordions extension for Joomla contains a privileged stored XSS flaw in its rtla‑alias option. The option value is inserted unescaped into a JavaScript string that is itself embedded in an HTML onclick attribute, allowing an attacker to craft a data‑rlta‑alias that changes the generated handler. This flaw permits the execution of arbitrary script in the browser context of any user who views the affected page, potentially enabling session hijacking, credential theft, or defacement.
Affected Systems
The vulnerability affects all installations of the regularlabs.com Tabs & Accordions extension for Joomla—both the free and the pro editions—when the extension version is less than 3.1.0. No specific Joomla version is listed, so any Joomla site using a pre‑3.1.0 Tabs & Accordions component is likely exposed.
Risk and Exploitability
The CVSS score of 7.5 indicates a high level of risk. EPSS is less than 1%, suggesting a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no known exploits currently. The attack vector is inferred to be a privileged attacker who can supply a crafted data‑rlta‑alias value, to the affected page.
OpenCVE Enrichment