Impact
The Easy Store extension for Joomla contains a flaw in the ApiController.php file where the allowEdit() method always returns true. This bypasses Joomla’s component‑level and asset‑level access control checks, letting any authenticated backend user modify any Easy Store record. As a result, unauthorised users can change product data, orders, or other sensitive information, compromising data integrity and potentially enabling further malicious actions.
Affected Systems
The vulnerability affects the joomshaper.com Easy Store extension for Joomla, versions 1.0.0 through 3.0.0. Any site running one of these releases is impacted.
Risk and Exploitability
The CVSS score is 8.6, indicating high severity. The EPSS score is not available, so the current exploitation likelihood is unclear, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only that the attacker be a legitimate backend user; no external network access is needed. Once authenticated, an attacker can elevate privileges within the Easy Store component and inject unauthorized changes to records.
OpenCVE Enrichment