CVE-2026-75950

Summary

Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already had an owner. 6.2.3 binds the action to the authenticated user and only allows unowned listings.

Affected Software

VendorProductVersion RangeStatus
cmsjunkie.comJ-BusinessDirectory extension for Joomla1.0.0-6.2.2affected

Weaknesses

  • CWE-284: CWE-284 Improper Access Control
  • CWE-639: CWE-639 (Authorization Bypass Through User-Controlled Key)

References