CyberRota Analysis
AI-GeneratedThe YOOtheme Pro extension for Joomla versions 2.3.0 to 5.0.40 is vulnerable to a glob-based pattern attack that permits authenticated, privileged users to read arbitrary files on the server. This vulnerability could lead to unauthorized access to sensitive information, potentially compromising the integrity and confidentiality of the affected system. Organizations using this extension should prioritize patching to mitigate the risk of exploitation.
Original NVD Description
Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 - The Filesystem source's path filter is vulnerable to glob-based pattern attacks, allowing authorized users to read arbitrary files.