CVE-2026-75953
N/A
N/A
Summary
Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitrary address.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| cmsjunkie.com | J-BusinessDirectory extension for Joomla | 1.0.0-6.2.2 | affected |
Weaknesses
- CWE-201: CWE-201: Insertion of Sensitive Information Into Sent Data
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.