CyberRota Analysis
AI-GeneratedThe Easy Store extension for Joomla is vulnerable due to inadequate CSRF token verification across multiple administrative AJAX API endpoints, allowing attackers to exploit this weakness and perform unauthorized state changes in the store backend. This high-severity vulnerability poses a significant risk to any Joomla site using the affected extension, particularly those with administrative access. Joomla administrators and security teams should prioritize applying the patch to mitigate potential exploitation.
Original NVD Description
Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0 - The administrator ApiController only validated CSRF tokens inside the products() action. All other administrative AJAX endpoints (orders, coupons, media, customers, settings, tags, categories, reviews, and collections) accepted state-changing requests without checking anti-CSRF tokens. An attacker could trick a logged-in administrator into triggering unauthorized state modifications across the store backend. Resolved by implementing global CSRF verification in ApiController::execute() for all state-changing HTTP methods (POST, PUT, PATCH, DELETE) via Session::checkToken().