Joomla 插件 - j2commerce.com - J2Store 1.0.0-3.3.21、4.0.0-4.0.21 和 4.1.0-4.1.6 中,通过 、 和 参数触发反射型跨站脚本(XSS)。四个任务处理程序接受来自用户输入的 Base64 编码 URL,并在未验证目标主机名的情况下直接重定向,从而允许攻击者利用该商店受信任的域名进行钓鱼攻击。此漏洞无需身份验证即可利用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| j2commerce.com | J2Store extension for Joomla | 1.0.0-3.3.21 |
affected |
4.0.0-4.0.21 |
affected | ||
4.1.0-4.1.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| j2commerce.com | J2Store extension for Joomla | 1.0.0-3.3.21 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78069 | 9.5 CRITICAL | Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation ch |
| CVE-2026-78064 | 8.8 HIGH | Joomla Extension - j2commerce.com - Anonymous cart-record tampering via inherited FOF `sav |
| CVE-2026-77999 | 8.7 HIGH | Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to ord |
| CVE-2026-78065 | 7.1 HIGH | Joomla Extension - j2commerce.com - Guest checkout address disclosure to any authenticated |
No comments yet