GHSA-cpjv-mhxq-9xqfMediumCVSS 4.3
Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers...
🔗 CVE IDs covered (1)
📋 Description
Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML forms targeting account endpoints like /joomoc2/?route=account/edit and to modify user information or reset passwords without user consent.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2018-25337
- https://extensions.joomla.org/extensions/extension/e-commerce/e-commerce-integrations/joomocshop
- https://www.exploit-db.com/exploits/44789
- https://www.joomlaextensions.co.in
- https://www.vulncheck.com/advisories/joomla-joomocshop-cross-site-request-forgery
- https://github.com/advisories/GHSA-cpjv-mhxq-9xqf