Impact
An unauthenticated attacker can inject arbitrary SQL through the a[] and s[] GET parameters on the public shop items page of Phoca Cart. The flaw does not involve parameterization or escaping, allowing a blind SQL injection that can extract the entire database. This can compromise the confidentiality of all stored data, potentially exposing customer records, financial information, and other sensitive content used by the Joomla site.
Affected Systems
The vulnerability affects the Phoca Cart extension for Joomla, versions 5.0.0 through 6.1.6. Any Joomla installation that has Phoca Cart within this range and exposes the shop items page publicly is susceptible.
Risk and Exploitability
With a CVSS base score of 9.3, this flaw carries a high likelihood of exploitation when accessible over the network, though the EPSS score is not available. The flaw is not listed in CISA KEV, which suggests no known active exploitation campaigns yet, but the nature of the attack vector—an unauthenticated attacker accessing a public URL—and the use of time‑based blind techniques increase its practical risk. An attacker could leverage the injection to exfiltrate data or potentially pivot to other parts of the database if additional privileges exist.
OpenCVE Enrichment