Impact
The J‑BusinessDirectory extension for Joomla contains an open mail relay flaw; it uses an address supplied in the request parameters instead of a validated server‑side value, permitting any sender to specify the recipient. This can be abused to send spam, phishing, or other malicious messages from the affected server, compromising its reputation and potentially violating email policies.
Affected Systems
Any Joomla site that has the cmsjunkie.com J‑BusinessDirectory extension installed with a version newer than 6.2.3 is unaffected; sites running any prior version are vulnerable. The extension alone is the scope; core Joomla components are not impacted.
Risk and Exploitability
An attacker can trigger the flaw by submitting a crafted HTTP request that includes a contact identifier. No authentication is required, making it a purely remote web‑based threat. The CVSS score of 7.5 indicates high severity, while the EPSS score is below 1% – a very low but non‑zero likelihood of exploitation – and the vulnerability is not listed in the CISA KEV database, yet the lack of a mitigation makes the risk high for all affected installations.
OpenCVE Enrichment