Impact
The J‑BusinessDirectory extension for Joomla is vulnerable to an insecure direct object reference through multiple frontend and API actions. An attacker can directly substitute an object identifier in a request to bypass authorization controls, allowing unauthorized viewing or modification of protected data such as business listings. This flaw is classified as CWE‑639, which indicates that proper access control checks are missing during object reference handling.
Affected Systems
The affected vendor is cmsjunkie.com, offering the J‑BusinessDirectory extension for Joomla. Versions of the extension earlier than 6.2.3 are affected by this IDOR flaw, as indicated by the version constraint "< 6.2.3". Users running the extension in any Joomla site should verify their installed version and assume any build prior to 6.2.3 is vulnerable.
Risk and Exploitability
The CVSS score of 6.9 reflects a moderate to high risk of exploitation, and the EPSS score is less than 1%. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely via the web interface or API without needing privileged access, inferring that the likely attack vector is through crafted HTTP requests that alter object identifiers. Because the flaw does not allow code execution, the immediate threat manifests as unauthorized data exposure or tampering rather than full system compromise.
OpenCVE Enrichment