Impact
The vulnerability allows a lower‑privileged author to supply executable code through the Modals Pro extension for Joomla’s event handler options such as on-open and on-closed. The extension treats this code as trusted, storing it in the article content and rendering it in the browser without proper escaping. Consequently, any author who can publish or edit an article can embed script that will execute with the privileges of the user viewing the modal, enabling session hijacking, cookie theft, or the execution of arbitrary actions on the site. This flaw is categorised as a stored XSS attack, mapped to CWE‑79.
Affected Systems
The affected product is the Modals (Pro) extension by regularlabs.com, installed in Joomla sites that use any version older than 17.0.0. No specific build or patch numbers are mentioned beyond the version cutoff, so any deployment below 17.0.0 is potentially vulnerable.
Risk and Exploitability
The CVSS base score of 7.5 classifies the issue as high severity. The EPSS score is < 1%, and the vulnerability is not listed in the KEV catalog, implying no publicly confirmed exploits yet. Nonetheless, the nature of the flaw—a stored XSS—makes it relatively easy for an attacker with article‑author privileges to craft the malicious payload, as the code is executed in the context of any visitor to the affected page. The likely attack vector is through normal user‑generated content channels within Joomla, meaning organizations that allow article authors without stringent review controls face considerable risk.
OpenCVE Enrichment