Joomla 扩展 - j2commerce.com - J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 中通过继承的 FOF 任务实现匿名用户篡改购物车记录 授予 视图任务通配符 的访问控制列表(ACL),而 FOF 仅对后台 HTML 请求强制校验 CSRF 令牌,对前端 请求则不进行校验。 已将 操作限定在调用者自身的会话范围内,但从未重写通用的 FOF 任务,导致攻击者可以通过指定任意的 / 插入新的购物车记录,或者通过 id 覆盖现有的购物车记录。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| j2commerce.com | J2Store extension for Joomla | 1.0.0-3.3.21 |
affected |
4.0.0-4.0.21 |
affected | ||
4.1.0-4.1.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| j2commerce.com | J2Store extension for Joomla | 1.0.0-3.3.21 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78069 | 9.5 CRITICAL | Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation ch |
| CVE-2026-77999 | 8.7 HIGH | Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to ord |
| CVE-2026-78065 | 7.1 HIGH | Joomla Extension - j2commerce.com - Guest checkout address disclosure to any authenticated |
| CVE-2026-78000 | 5.3 MEDIUM | Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3. |
No comments yet