Impact
The vulnerability is an unauthenticated SQL injection in the Easy Store extension for Joomla caused by improper validation of order parameters. Attackers can inject arbitrary SQL that allows reading the entire database, including user credentials and session data, which directly compromises confidentiality and may enable account takeover. This impact is based on the description’s explicit mention of full DB read access.
Affected Systems
The affected component is the Easy Store extension for Joomla provided by joomshaper.com. Versions 1.0.0 through 2.0.1 are vulnerable.
Risk and Exploitability
With a CVSS score of 9.3, the flaw is considered critical. The EPSS score of less than 1% indicates a low probability of broad exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The vulnerability is unauthenticated and relies on standard web requests targeting order parameters; therefore the likely attack vector is network‑based and application‑level, meaning any remote user who can reach the Joomla site can potentially exploit it by sending crafted requests to the vulnerable endpoint. The impact is full database read access, which can lead to significant data exposure and potentially account compromise, although the latter is inferred from the database breach potential and not explicitly stated in the description.
OpenCVE Enrichment