Joomla 扩展 - phoca.cz - Phoca Cart 5.0.0 至 6.1.8 版本中,订单查看功能存在通过用户可控键值的授权绕过漏洞(IDOR)。Phoca Cart 的订单文件下载接口未对其请求的下载令牌进行验证。参数 (下载令牌)和 (订单令牌)仅被检查是否为非空值,系统从未将它们与存储的 / 值进行比对。因此,任何远程用户(包括完全没有账户的访客)都可以通过枚举连续的 ID 值并提供任意非空的令牌,下载任何客户的数字商品。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| phoca.cz | Phoca Cart extension for Joomla | 5.0.0-6.1.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| phoca.cz | Phoca Cart extension for Joomla | 5.0.0-6.1.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet