Joomla 扩展 - j2commerce.com - J2Store 1.0.0-3.3.2、4.0.0-4.0.22 和 4.1.0-4.1.7 中,PayPal 通知重定向反射了未经转义的请求数据 攻击者可以构造指向 PayPal 通知(notify)端点的恶意链接。如果受害者的浏览器(或自动抓取该链接的系统)访问了该链接,则随后跳转至 组件的结账控制器时,会携带攻击者任意指定的查询参数,而不仅仅是预期的 参数组——这实质上构成了向后续请求注入或“夹带”恶意参数的行为。 此漏洞需要受害者实际加载该恶意链接才
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| j2commerce.com | J2Store extension for Joomla | 1.0.0-3.3.22 |
affected |
4.0.0-4.0.22 |
affected | ||
4.1.0-4.1.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| j2commerce.com | J2Store extension for Joomla | 1.0.0-3.3.22 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82189 | 8.7 HIGH | Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1. |
| CVE-2026-81568 | 8.7 HIGH | Joomla Extension - j2commerce.com - Arbitrary file read via `task=download` in J2Store 1.0 |
| CVE-2026-81567 | 8.7 HIGH | Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront |
| CVE-2026-78081 | 7.1 HIGH | Joomla Extension - j2commerce.com - Missing CSRF protection on cart, checkout and myprofil |
| CVE-2026-82190 | 6.3 MEDIUM | Joomla Extension - j2commerce.com - Predictable/forgeable order access token in J2Store 1. |
No comments yet