Anonymous Cart-Record Tampering in J2Store by Joomla Extension
CVE-2026-78064
8.8HIGH
What is CVE-2026-78064?
The vulnerability presents an access control issue within the J2Store Joomla extension, allowing unauthorized users to tamper with cart records. Through a flawed implementation of the FOF save task, an attacker can exploit a wildcard ACL setting that grants unrestricted access to modify cart entries. This oversight enables the insertion of cart rows with arbitrary user identifiers and session details or the alteration of existing entries by their IDs. Notably, the vulnerability only enforces CSRF protections on backend requests, making it easier for attackers to manipulate cart data through frontend interactions.
Affected Version(s)
J2Store extension for Joomla 1.0.0-3.3.21
J2Store extension for Joomla 4.0.0-4.0.21
J2Store extension for Joomla 4.1.0-4.1.6
