Description
Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML forms targeting account endpoints like /joomoc2/?route=account/edit and to modify user information or reset passwords without user consent.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
Credits
L0RD or borna.nematzadeh123@gmail.com
References
www.exploit-db.com/exploits/44789 (ExploitDB-44789)
www.joomlaextensions.co.in/ (Official Product Homepage)
extensions.joomla.org/...e-commerce-integrations/joomocshop/ (Product Reference)
www.vulncheck.com/...a-joomocshop-cross-site-request-forgery (VulnCheck Advisory: Joomla JoomOCShop 1.0 Cross-Site Request Forgery)