Executive brief
Regular Labs Modals Pro, a popular extension for the Joomla content management system used to create popup windows, contains a security flaw. This vulnerability allows an attacker to view or list files and directories on the web server that should normally be restricted. This could lead to the exposure of sensitive configuration files or internal system information, potentially aiding further attacks against the website.
Technical details
A path traversal vulnerability (CWE-22) exists in the Regular Labs Modals Pro extension for Joomla, versions 1.0.0 through 15.0.0. The flaw resides in how the extension handles gallery paths, failing to properly sanitize input used to construct file system paths. A remote attacker can exploit this to enumerate directories and potentially access files outside of the intended web root or gallery folders. The vulnerability was reported by the Joomla! Project and affects the Pro version of the extension.
Affected products
- Regular Labs Modals Pro extension for Joomla 1.0.0-15.0.0
Timeline
- 2026-07-23: disclosed: CVE published by NVD and Joomla! Project