GHSA-cpjv-mhxq-9xqfMediumCVSS 4.3

Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers...

Published
May 17, 2026
Last Modified
May 17, 2026

🔗 CVE IDs covered (1)

📋 Description

Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML forms targeting account endpoints like /joomoc2/?route=account/edit and to modify user information or reset passwords without user consent.

🔗 References (6)