CVE-2026-67360: Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user could supply another customer's orderid to copy their cart contents and address data into the attacker's session. The CSRF token was validated but ownership was not checked.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be an authenticated J2Store user and be able to provide another customer's order_id. The issue allows copying that customer's cart contents and address data into the attacker's own session.
Does CSRF protection prevent exploitation?
No. The CSRF token was validated, but the affected functionality did not verify that the supplied order_id belonged to the authenticated user.
Which J2Store versions are affected?
Affected versions are 1.0.0 through 3.3.20, 4.0.0 through 4.0.20, and 4.1.0 through 4.1.5.