漏洞标题:Joomla 扩展 – j2commerce.com – J2Store 1.0.0–3.3.20、4.0.0–4.0.20、4.1.0–4.1.5 中存在跨客户订单复制漏洞 漏洞描述: 在 J2Store 版本 1.0.0 至 3.3.20、4.0.0 至 4.0.20 以及 4.1.0 至 4.1.5 中,存在跨客户订单复制漏洞。经过身份验证的恶意用户可以提供其他客户的 order_id,从而将其购物车内容和地址数据复制到攻击者自身的会话中。尽管该操作通过了 CSRF(跨站请求伪造)令牌验证,但系统未
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| j2commerce.com | J2Store extension for Joomla | 1.0.0-3.3.20 |
affected |
4.0.0-4.0.20 |
affected | ||
4.1.0-4.1.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| j2commerce.com | J2Store extension for Joomla | 1.0.0-3.3.20 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67359 | 8.7 HIGH | Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3.3.20, 4.0.0-4 |
| CVE-2026-74252 | 8.6 HIGH | Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, |
| CVE-2026-67361 | 6.9 MEDIUM | Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory pro |
| CVE-2026-67358 | 5.3 MEDIUM | Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4 |
| CVE-2026-67362 | 5.1 MEDIUM | Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3. |
No comments yet