CyberRota Analysis
AI-GeneratedThe YOOtheme Pro extension for Joomla is vulnerable due to a missing access check, allowing users with template editing permissions to access sensitive information about arbitrary modules without the necessary module permissions. This could lead to unauthorized information disclosure, potentially exposing critical data to users who should not have access. Joomla site administrators and developers using YOOtheme Pro should prioritize this vulnerability to mitigate the risk of data leaks.
Original NVD Description
Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A missing access check allowed users with com_template editing permissions to access information about arbitrary modules without the respective com_modules permissions.