Joomla 扩展 - j2commerce.com - J2Store 1.0.0-3.3.2、4.0.0-4.0.22、4.1.0-4.1.7 中通过 实现任意文件读取 在 J2Store 中, 方法通过将配置的附件文件夹与产品文件的 (即存储的文件名)进行拼接,构建已购买数字下载文件的磁盘路径。该方法仅使用了 (仅规范化路径分隔符,但不会解析或过滤 路径段)和一个简单的 检查,但从未验证解析后的路径是否仍然位于配置的附件文件夹内。 如果某个产品文件的 中包含 路径遍历片段——最可能的情况是通过问题 1 中描述
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| j2commerce.com | J2Store extension for Joomla | 1.0.0-3.3.22 |
affected |
4.0.0-4.0.22 |
affected | ||
4.1.0-4.1.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| j2commerce.com | J2Store extension for Joomla | 1.0.0-3.3.22 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82189 | 8.7 HIGH | Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1. |
| CVE-2026-81567 | 8.7 HIGH | Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront |
| CVE-2026-78081 | 7.1 HIGH | Joomla Extension - j2commerce.com - Missing CSRF protection on cart, checkout and myprofil |
| CVE-2026-82190 | 6.3 MEDIUM | Joomla Extension - j2commerce.com - Predictable/forgeable order access token in J2Store 1. |
| CVE-2026-82191 | 5.3 MEDIUM | Joomla Extension - j2commerce.com - Unescaped request data reflected into PayPal notify re |
No comments yet