Impact
The J2Store extension for Joomla contains a blind SQL injection vulnerability that is exploitable without authentication. An attacker can use boolean or time based inference to extract arbitrary content from the database, including customer records, order details, and stored credentials or tokens. This weakness is classified as CWE‑89 and directly compromises the confidentiality of all data accessible through the storefront product list or product‑tags filter.
Affected Systems
Affected products are the J2Store extension from j2commerce.com, bundled with Joomla. Vulnerable releases are 1.0.0 through 3.3.2, 4.0.0 through 4.0.22, and 4.1.0 through 4.1.7. The flaw is reachable through any public storefront that exposes the standard product listing or tags filter.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is not available, so the current exploitation probability is unknown, and the vulnerability is not yet listed in CISA KEV. The likely attack vector is via the public web interface; unauthenticated access to the product list or tags filter allows an attacker to perform blind inference and exfiltrate data remotely.
OpenCVE Enrichment