Joomla 扩展 – j2commerce.com – J2Store 1.0.0 至 3.3.2、4.0.0 至 4.0.22 以及 4.1.0 至 4.1.7 版本中,购物车、结账和个人资料控制器缺少 CSRF(跨站请求伪造)防护 —— 攻击者可以利用受害者处于活跃结账会话期间,伪造请求在订单确认前静默覆盖账单或收货地址。这是后果最为严重的子场景,因为它使得攻击者有机会将已付款订单的商品重定向到其控制的地址;或者通过 方法篡改已保存的个人资料地址。与之前类似,每个伪造请求仅能以受害者自身会话的权限执行,因此不
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| j2commerce.com | J2Store extension for Joomla | 1.0.0-3.3.22 |
affected |
4.0.0-4.0.22 |
affected | ||
4.1.0-4.1.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| j2commerce.com | J2Store extension for Joomla | 1.0.0-3.3.22 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82189 | 8.7 HIGH | Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1. |
| CVE-2026-81568 | 8.7 HIGH | Joomla Extension - j2commerce.com - Arbitrary file read via `task=download` in J2Store 1.0 |
| CVE-2026-81567 | 8.7 HIGH | Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront |
| CVE-2026-82190 | 6.3 MEDIUM | Joomla Extension - j2commerce.com - Predictable/forgeable order access token in J2Store 1. |
| CVE-2026-82191 | 5.3 MEDIUM | Joomla Extension - j2commerce.com - Unescaped request data reflected into PayPal notify re |
No comments yet