Impact
The vulnerability exists in the J2Store extension for Joomla and is caused by missing CSRF protection on the cart, checkout, and myprofile controllers. A forged request can be sent while a legitimate user has an active checkout session, silently changing the billing or shipping address before the order is confirmed. profile address via the saveAddress() method. The attack does not grant the attacker additional privileges or cross‑account access; it only affects the victim’s own session. However, the impact is significant because an attacker can redirect the delivery of paid merchandise to an address they control.
Affected Systems
The affected package is the J2Store extension for Joomla, distributed by j2commerce.com. Vulnerable versions are 1.0.0 through 3.3.2, 4.0.0 through 4.0.22, and 4.1.0 through 4.1.7.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires a moderately skilled attacker to coerce the victim into submitting a forged request; the attacker needs only the victim’s active session and the ability to craft or drive an HTTP request. Because the flaw does not require authentication beyond the victim’s existing rights, the path to exploitation is relatively straightforward and can be performed via a malicious link, phishing email or compromised iframe. Given the potential for financial loss, the risk remains significant even without a current exploitation statistic.
OpenCVE Enrichment