CVE-2026-75950: Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3
Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already had an owner. 6.2.3 binds the action to the authenticated user and only allows unowned listings.
Affected Software
Event History
Frequently Asked Questions
Which installations are affected?
J-BusinessDirectory versions earlier than 6.2.3 are affected. Version 6.2.3 changes the ownership action to bind it to the authenticated user and to allow only unowned listings.
What could an attacker do?
An unauthenticated attacker could supply company and user IDs to change a listing's ownership. This could affect listings that already had an owner.
What is the immediate mitigation?
Upgrade J-BusinessDirectory to version 6.2.3. The provided information does not describe a temporary workaround for installations that cannot yet be upgraded.