Joomla JoomOCShop Cross-Site Request Forgery Vulnerability

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in the Joomla JoomOCShop extension version 1.0. This vulnerability allows attackers to perform unauthorized actions on behalf of authenticated users. By crafting malicious HTML forms that target specific account endpoints, such as the user information edit route, attackers can modify user details or reset passwords without the user's consent.

Impact

Exploitation of this vulnerability allows for unauthorized actions to be performed on behalf of users, potentially leading to unauthorized changes in user information or password resets.

Reproduction

To exploit this vulnerability, create a malicious HTML form that includes the necessary fields for the targeted account endpoint. For example, to change user information, the form should be directed to the account edit route and include fields such as firstname, lastname, email, telephone, and fax. Once the form is prepared, it can be submitted automatically using a script.

Added: May 17, 2026, 1:23 PM
Updated: May 17, 2026, 1:23 PM

Vulnerability Rating

Custom Algorithm
spread
7.6
impact
2.5
exploitability
7.3
remediation
0.0
relevance
8.6
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.