Cross-Site Request Forgery Vulnerability in Joomla jCart for OpenCart
CVE-2018-25336
Key Information:
- Vendor
Joomlaextensions
- Vendor
- CVE Published:
- 17 May 2026
Badges
What is CVE-2018-25336?
Joomla jCart for OpenCart version 2.3.0.2 is susceptible to a cross-site request forgery vulnerability that enables attackers to alter user account details illicitly. By crafting malicious HTML forms targeting specific endpoints, unauthorized individuals can modify user credentials, passwords, and affiliate account settings when users inadvertently engage with an attacker-controlled webpage. This vulnerability emphasizes the need for robust security measures to protect user data from manipulation.
Affected Version(s)
Joomla! extension jCart for OpenCart 2.3.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
