Impact
The vulnerability allows an unauthenticated attacker to store arbitrary HTML in the guest checkout billing address fields, enabling the execution of malicious JavaScript when site visitors view the affected content; this results in cross‑site scripting with potential theft of credentials, session hijacking, or defacement. The flaw is a classic example of CWE‑79: Improper Neutralization of Input During Web Page Generation.
Affected Systems
J2Store extension for Joomla, versions 1.0.0 through 3.3.20, 4.0.0 through 4.0.20, and 4.1.0 through 4.1.5, are affected.
Risk and Exploitability
With a CVSS score of 8.6 the weakness is considered high severity. The EPSS score is not available, so the probability of exploitation cannot be quantified currently, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated user submitting a guest checkout form on a public e‑commerce site, a scenario that is common for many installations.
OpenCVE Enrichment