Impact
The J-BusinessDirectory extension for Joomla with versions prior to 6.2.3 contains a flaw that permits an unauthenticated attacker to assign any company and user identifiers to a business listing, effectively transferring ownership. This can be performed even on listings that already have an owner, allowing the attacker to hoist existing listings into their control. As a result, authorized users lose control of their listings, which can be used to spread misinformation, steal reputational value, or conduct fraudulent activity. The weakness corresponds to improper access control (CWE-284) and unauthorized modification of resources (CWE-639).
Affected Systems
The affected system is the J-BusinessDirectory extension for Joomla created by cmsjunkie.com. All releases before version 6.2.3 are vulnerable. Users employing these earlier releases should verify and upgrade accordingly.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating moderate severity. The EPSS score is 0.00295, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote, web-based interaction where an attacker sends HTTP requests to the vulnerable endpoint without needing prior authentication. Because the flaw allows assignment of arbitrary company and user identifiers—including overriding existing owners—an attacker can takeover listings and compromise their integrity and the trustworthiness of the platform.
OpenCVE Enrichment