Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.j2commerce.com/ |
|
Thu, 03 Sep 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
J2commerce.com
J2commerce.com j2store Extension For Joomla |
|
| Vendors & Products |
J2commerce.com
J2commerce.com j2store Extension For Joomla |
Thu, 03 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla Extension - j2commerce.com - Guest checkout address disclosure to any authenticated user (IDOR) in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `editAddress()` redirected non-owners away only when the loaded address row had a **non-empty** `user_id` belonging to someone else. Guest-checkout address rows have an empty `user_id`, so that check never triggered for them — any logged-in account guessing a small, sequential `address_id` got a guest customer's full name, street address, and phone number rendered prefilled into the edit form. | |
| Title | Joomla Extension - j2commerce.com - Guest checkout address disclosure to any authenticated user (IDOR) in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2026-09-03T13:18:49.025Z
Reserved: 2026-08-22T11:33:08.526Z
Link: CVE-2026-78065
Updated: 2026-09-03T13:02:16.186Z
Status : Received
Published: 2026-09-03T13:06:09.200
Modified: 2026-09-03T14:17:01.157
Link: CVE-2026-78065
No data.
OpenCVE Enrichment
Updated: 2026-09-03T13:45:04Z