CyberRota Analysis
AI-GeneratedThe Phoca Cart extension for Joomla versions 5.0.0 to 6.1.8 is vulnerable to an authorization bypass due to inadequate validation of download tokens, allowing remote users, including unauthenticated guests, to access and download any customer's digital goods by manipulating the token parameters. This vulnerability poses a significant risk of data exposure and unauthorized access to sensitive customer information. Organizations using this extension should prioritize immediate remediation to protect their digital assets and customer data.
Original NVD Description
Joomla Extension - phoca.cz - Authorisation bypass through user-controlled key (IDOR) in Order View in Phoca Cart 5.0.0 - 6.1.8 - Phoca Cart's order-file download endpoint does not verify the download tokens it asks for. The d (download token) and o (order token) parameters are checked for non-emptiness only — they are never compared to the stored download_token / order_token values. As a result, any remote user (including a guest with no account at all) can download any customer's digital goods by enumerating sequential id values and supplying arbitrary non-empty tokens.