CVE-2026-77999
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Summary
Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - The PayPal IPN listener's signature check (_validateIPN()) accepted UNVERIFIED and any non-INVALID response as valid, made its verification request with CURLOPT_SSL_VERIFYPEER disabled, and stored its verdict in a field nothing downstream ever checked — so processing continued regardless of the outcome. Separately, the paid-amount comparison only ran when mc_gross was a positive number; omitting the field from the POST body (floatval(null) == 0) skipped the check entirely. Combined with a merchant-configured receiver_email and a sequential, enumerable order id read from the custom field, an anonymous POST was enough to move a pending order straight to CONFIRMED with no payment, or force another customer's pending order to FAILED. paypalv2.php performed no amount check under any circumstances.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| j2commerce.com | J2Store extension for Joomla | 1.0.0-3.3.21 | affected |
| j2commerce.com | J2Store extension for Joomla | 4.0.0-4.0.21 | affected |
| j2commerce.com | J2Store extension for Joomla | 4.1.0-4.1.6 | affected |
Weaknesses
- CWE-472: CWE-472: External Control of Assumed-Immutable Web Parameter
- CWE-602: CWE-602: Client-Side Enforcement of Server-Side Security
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.