CVE-2026-67361
6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:A/R:A
Summary
Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - The file upload endpoint accepted POST requests from unauthenticated visitors with no CSRF token. Compounding this, the installer manifest omitted the upload and invoices directories, causing fresh installs to deploy those directories without .htaccess/web.config protection, making uploaded files directly web-accessible.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| j2commerce.com | J2Store extension for Joomla | 1.0.0-3.3.20 | affected |
| j2commerce.com | J2Store extension for Joomla | 4.0.0-4.0.20 | affected |
| j2commerce.com | J2Store extension for Joomla | 4.1.0-4.1.5 | affected |
Weaknesses
- CWE-352: CWE-352 Cross-Site Request Forgery (CSRF)
- CWE-538: CWE-538 (Insertion of Sensitive Information into Externally-Accessible File or Directory)
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.