CyberRota Analysis
AI-GeneratedThe Easy Store extension for Joomla versions 1.0.0 to 2.0.1 is vulnerable to an unauthenticated SQL injection due to improper validation of order parameters. This flaw allows attackers to execute arbitrary SQL queries, potentially granting them full access to the database, including sensitive information such as credentials and session data. Joomla site administrators using this extension should prioritize remediation to prevent unauthorized data access.
Original NVD Description
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions.