Impact
The vulnerability allows an authenticated user to supply another customer’s order_id to copy their cart contents and address data into the attacker’s session. Although a CSRF token is validated, the ownership of the order is not checked, resulting in unauthorized data exposure.
Affected Systems
Affected systems are the J2Store extension for Joomla distributed by j2commerce.com. Versions 1.0.0 through 3.3.20, 4.0.0 through 4.0.20, and 4.1.0 through 4.1.5 are impacted.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity, and the lack of an EPSS score or KEV listing suggests the vulnerability has not yet been widely exploited. Attackers must be authenticated, but once logged in they can extract another user’s personal order details without authorization, posing privacy and potential data leakage risks. Proper ownership checks or disabling the replication feature can mitigate the risk.
OpenCVE Enrichment