CVE-2026-75952: Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3

Published Aug 19, 2026
·
Updated

Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Tokens were missing on many AJAX/state-changing tasks: contact/quote forms, cart, bookmarks, uploads, messages, AI text generation, and several administrator actions (app install, demo-data wipe, cache/statistics archive, payment notification send, mobile push). Frontend CSRF needs a registered/listing-owner session; admin CSRF needs a backend admin session.

Affected Software

1 affected component
J-BusinessDirectory<6.2.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Joomla Extension - cmsjunkie.com - J-BusinessDirectory to a version that resolves this vulnerability.

    Fixed in 6.2.3
  2. Configuration

    Ensure CSRF-protected endpoints enforce the required session context: frontend CSRF must require a registered/listing-owner session, and admin CSRF must require a backend admin session (especially for AJAX/state-changing tasks such as contact/quote forms, cart, bookmarks, uploads, messages, AI text generation, and administrator actions like app install, demo-data wipe, cache/statistics archive, payment notification send, and mobile push).

    Joomla Extension - cmsjunkie.com - J-BusinessDirectory session_requirements_for_csrf = registered/listing-owner session for frontend; backend admin session for admin operations

Event History

Aug 19, 2026
CVE Published
via MITRE·02:46 PM
Data Sourced
via MITRE·02:46 PM
DescriptionWeakness

Frequently Asked Questions

1

Can an unauthenticated visitor be used to exploit the frontend issue?

Frontend exploitation requires a victim with an active registered-user or listing-owner session. The provided information does not indicate that unauthenticated-only exploitation is possible.

2

What level of access must a victim have for administrator-side actions to be triggered?

Administrator-side CSRF requires a victim with an active backend administrator session. A successful attack could target actions including app installation, demo-data deletion, cache or statistics archiving, payment-notification sending, and mobile push operations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203