Impact
An unescaped request value is taken from a request sent to the PayPal notification endpoint and inserted directly into the redirect URL that forwards the browser to the site’s checkout controller. The injected value becomes an additional query string component of the redirect, allowing an attacker to choose arbitrary parameters such as view, task, orderpayment_type, or paction. This type of flaw is a parameter injection weakness that can bypass the application’s regular request filtering, but it does not grant an attacker anything beyond what could be achieved by composing the same checkout URLCustomers using the J2Store extension for Joomla from j2commerce.com are affected. The flaw exists in extension versions 1.0.0 through 3.3.2, 4.0.0 through 4.0.22, and 4.1.0 through 4.1.7.
Affected Systems
The J2Store extension for Joomla from j2commerce.com is affected across versions 1.0.0 through 3.3.2, 4.0.0 through 4.0.22, and 4.1.0 through 4.1.7.
Risk and Exploitability
The CVSS rating of 5.3 indicates a medium severity impact. The EPSS score is 0.00264, indicating a very low but nonzero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting current exploit activity is unknown. Attack requires a notification endpoint, so the threat model is limited to user interaction or automated fetching of the URL. Even with a successful redirect, the attacker cannot gain additional privileges beyond what could be achieved by simply requesting the. Overall risk is moderate, reflecting the need for mitigation while notingimpact by itself.
OpenCVE Enrichment