CyberRota Analysis
AI-GeneratedThe Modals extension for Joomla versions prior to 17.0.0 is vulnerable to a privileged stored cross-site scripting (XSS) attack due to improper handling of executable URL schemes. This flaw allows attackers to inject malicious JavaScript into user browsers, potentially compromising user data and session integrity. Joomla site administrators and developers using the Modals extension should prioritize patching this vulnerability to protect their users from exploitation.
Original NVD Description
Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0 - Modals treats a destination using an executable browser URL scheme as an ordinary modal URL. The value can reach both the generated link and the iframe-loading path. Authored content can consequently become JavaScript in a visitor's browser without using Modals' separate Pro JavaScript Events feature.