CyberRota Analysis
AI-GeneratedAn authenticated user of the J2Store extension for Joomla can exploit a vulnerability that allows them to replicate another customer's cart contents and address data by providing a different order ID. This cross-customer order replication poses a risk of unauthorized access to sensitive customer information. Joomla site administrators using affected versions should prioritize applying patches to mitigate potential data breaches and protect customer privacy.
Original NVD Description
Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user could supply another customer's order_id to copy their cart contents and address data into the attacker's session. The CSRF token was validated but ownership was not checked.