Cross-Site Request Forgery in J-BusinessDirectory by cmsjunkie.com
CVE-2026-75952
4.6MEDIUM
What is CVE-2026-75952?
A significant cross-site request forgery vulnerability exists in the J-BusinessDirectory extension developed by cmsjunkie.com, affecting all versions prior to 6.2.3. This flaw arises from the absence of security tokens for various AJAX and state-changing operations, including contact forms, cart activities, and administrative tasks such as app installations and mobile push notifications. Exploiting this vulnerability could allow unauthorized users to perform actions on behalf of legitimate users, compromising user data and undermining the integrity of web operations.
Affected Version(s)
J-BusinessDirectory extension for Joomla 1.0.0-6.2.2
