Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-78065— Joomla Extension - j2commerce.com - Guest checkout address disclosure to any authenticated user (IDOR) in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6

Quick assessment

Affected
j2commerce.com J2Store extension for Joomla
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Joomla 扩展 —— j2commerce.com —— J2Store 中向任意已认证用户披露访客结账地址(IDOR 漏洞) 受影响版本:1.0.0–3.3.21、4.0.0–4.0.21、4.1.0–4.1.6 漏洞描述: 在 函数中,只有当所加载的地址记录中的 非空且属于其他用户时,才会将非所有者重定向出去。然而,访客(guest)结账时创建地址记录的 为空,因此该检查对访客地址从不触发。结果是,任何已登录账户只要猜测到较小且连续递增的 ,就能在编辑表单中看到预先填充的访客客户的完整姓名、街道地址和电话号

CVSS 7.1 · High EPSS 0.21% · P11

Affected Version Matrix 3

VendorProduct Version RangeStatus
j2commerce.com J2Store extension for Joomla 1.0.0-3.3.21 affected
4.0.0-4.0.21 affected
4.1.0-4.1.6 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-78065

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Joomla Extension - j2commerce.com - Guest checkout address disclosure to any authenticated user (IDOR) in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6
Source: CVE Program / CVE List V5
Vulnerability Description
Joomla Extension - j2commerce.com - Guest checkout address disclosure to any authenticated user (IDOR) in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `editAddress()` redirected non-owners away only when the loaded address row had a **non-empty** `user_id` belonging to someone else. Guest-checkout address rows have an empty `user_id`, so that check never triggered for them — any logged-in account guessing a small, sequential `address_id` got a guest customer's full name, street address, and phone number rendered prefilled into the edit form.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
j2commerce.com J2Store extension for Joomla 1.0.0-3.3.21 -

II. Public POCs for CVE-2026-78065

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-78065

登录查看更多情报信息。

Vendor Pages for CVE-2026-78065 (1)

Same Patch Batch · j2commerce.com · 2026-09-03 · 5 CVEs total

CVE-2026-78069 9.5 CRITICAL Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation ch
CVE-2026-78064 8.8 HIGH Joomla Extension - j2commerce.com - Anonymous cart-record tampering via inherited FOF `sav
CVE-2026-77999 8.7 HIGH Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to ord
CVE-2026-78000 5.3 MEDIUM Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.

IV. Related Vulnerabilities

V. Comments for CVE-2026-78065

No comments yet


Leave a comment