Description
Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitrary address.
Published: 2026-08-19
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The J‑BusinessDirectory extension for Joomla contains an open mail relay flaw; it uses an address supplied in the request parameters instead of a validated server‑side value, permitting any sender to specify the recipient. This can be abused to send spam, phishing, or other malicious messages from the affected server, compromising its reputation and potentially violating email policies.

Affected Systems

Any Joomla site that has the cmsjunkie.com J‑BusinessDirectory extension installed with a version newer than 6.2.3 is unaffected; sites running any prior version are vulnerable. The extension alone is the scope; core Joomla components are not impacted.

Risk and Exploitability

An attacker can trigger the flaw by submitting a crafted HTTP request that includes a contact identifier. No authentication is required, making it a purely remote web‑based threat. The CVSS score of 7.5 indicates high severity, while the EPSS score is below 1% – a very low but non‑zero likelihood of exploitation – and the vulnerability is not listed in the CISA KEV database, yet the lack of a mitigation makes the risk high for all affected installations.

Generated by OpenCVE AI on August 26, 2026 at 20:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the J‑BusinessDirectory extension to version 6.2.3 or newer.
  • If an upgrade cannot be performed immediately, modify the extension to retrieve the recipient address from the server‑side offer or event record instead of the request parameters.
  • Restrict the extension’s use of the server’s SMTP service, or disable email sending until a reliable fix is applied.

Generated by OpenCVE AI on August 26, 2026 at 20:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Cmsjunkie.com
Cmsjunkie.com j-businessdirectory Extension For Joomla
Vendors & Products Cmsjunkie.com
Cmsjunkie.com j-businessdirectory Extension For Joomla

Wed, 19 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Description Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitrary address.
Title Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3
Weaknesses CWE-201
References

Subscriptions

Cmsjunkie.com J-businessdirectory Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-26T22:33:42.108Z

Reserved: 2026-08-18T16:11:15.469Z

Link: CVE-2026-75953

cve-icon Vulnrichment

Updated: 2026-08-26T18:03:57.752Z

cve-icon NVD

Status : Deferred

Published: 2026-08-19T15:18:09.940

Modified: 2026-08-26T19:17:03.897

Link: CVE-2026-75953

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T21:00:12Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data