Joomla 扩展程序 - cmsjunkie.com - J-BusinessDirectory 版本低于 6.2.3 中存在开放邮件中继漏洞 - 收件人地址从请求参数(contact_id_offer / contact_id_event)中获取,而不是从服务器端的报价/事件记录中获取,因此攻击者可以将邮件发送到任意地址。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| cmsjunkie.com | J-BusinessDirectory extension for Joomla | 1.0.0-6.2.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cmsjunkie.com | J-BusinessDirectory extension for Joomla | 1.0.0-6.2.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75949 | 10.0 CRITICAL | Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J |
| CVE-2026-75954 | 9.3 CRITICAL | Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < |
| CVE-2026-75956 | 8.7 HIGH | Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-Busine |
| CVE-2026-75951 | 6.9 MEDIUM | Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/AP |
| CVE-2026-75950 | 6.9 MEDIUM | Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-Busines |
| CVE-2026-75955 | 5.1 MEDIUM | Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < |
| CVE-2026-75952 | 4.6 MEDIUM | Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6. |
No comments yet