Impact
The J2Store extension for Joomla exposes a file upload endpoint that accepts POST requests from unauthenticated visitors without requiring a CSRF token. In addition, the installer manifest does not create protection files for the upload and invoices directories, so any files placed there are served directly by the web server. An attacker could therefore download the site, upload arbitrary files, and make them publicly reachable, possibly allowing the execution of malicious code on the host. This flaw directly compromises the confidentiality, integrity, and availability of the affected Joomla site.
Affected Systems
The vulnerability affects the J2Store extension provided by j2commerce.com for Joomla. Versions 1.0.0 through 3.3.20, 4.0.0 through 4.0.20, and 4.1.0 through 4.1.5 are impacted. All installations of the extension within these version ranges are at risk.
Risk and Exploitability
The CVSS score of 6.9 indicates medium‑to‑high severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting that it has not yet been widely exploited in the wild. The likely attack vector is over the web, as the vulnerable upload endpoint can be accessed without authentication. An attacker only needs HTTP access to the Joomla site; no additional privileges are required. Once a malicious file is uploaded, it is immediately web‑accessible, which creates the potential for remote code execution, defacement, or phishing vector deployment.
OpenCVE Enrichment