CyberRota Analysis
AI-GeneratedThe Modals Pro extension for Joomla versions prior to 17.0.0 is vulnerable to a stored cross-site scripting (XSS) attack due to improper handling of JavaScript event handlers, allowing lower-privileged users to inject malicious scripts. This vulnerability can lead to unauthorized actions and data exposure, posing a significant risk to website integrity and user security. Joomla site administrators and developers using the affected extension should prioritize immediate updates to mitigate potential exploitation.
Original NVD Description
Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0 - Modals Pro intentionally supports JavaScript Events such as on-open and on-closed. Affected versions do not distinguish trusted extension configuration from event code supplied in ordinary article content. A lower-privileged author can therefore use a documented executable feature which should be reserved for trusted authors.