Open Mail Relay Vulnerability in J-BusinessDirectory by cmsjunkie.com
CVE-2026-75953
Currently unrated
What is CVE-2026-75953?
The J-BusinessDirectory extension from cmsjunkie.com is vulnerable to an open mail relay issue, where the recipient address is erroneously derived from user input (contact_id_offer/contact_id_event) rather than being securely sourced from the server-side records. This flaw allows attackers to exploit the mailing functionality to send emails to arbitrary addresses, potentially facilitating email spoofing and privacy violations. Users of J-BusinessDirectory versions prior to 6.2.3 should take immediate steps to upgrade and secure their systems.
Affected Version(s)
J-BusinessDirectory extension for Joomla 1.0.0-6.2.2
