Impact
The Easy Store extension for Joomla lacks anti‑CSRF checks and fails to verify that the caller has administrative rights when updating site configuration. The endpoint administrator/index.php?option=com_easystore&task=appconfig.updateConfiguration allows a malicious site to inject forged requests from an administrator’s browser and silently change the Joomla mail sender name and address. This can lead to spam or phishing emails appearing to originate from the compromised site. Because the vulnerability permits modification of configuration data, attackers can alter how the site sends email, potentially disrupting legitimate communications or creating deceptive messages.\nThe likely attack vector is a cross‑site request forgery performed by a malicious external site leveraging an active administrator session.
Affected Systems
Vendors and products impacted are joomshaper.com's Easy Store extension for Joomla, specifically all released versions from 1.0.0 through 3.0.0.
Risk and Exploitability
With a CVSS score of 7.2, the vulnerability is classified as medium‑to‑high severity. The EPSS score is currently unavailable, so precise exploitation likelihood is unknown, but the absence of CSRF protection and weak access control suggests the exploitability is high for sites where administrators frequently log in from trusted networks. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation at this time.
OpenCVE Enrichment