vendor:
JoomOCShop
by:
L0RD
5.5
CVSS
MEDIUM
Cross site request forgery
Cross-Site Request Forgery (CSRF)
CWE
Product Name: JoomOCShop
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:joomlacommunity:joomocshop:1.0
Platforms Tested: Kali Linux
2018
Joomla! extension JoomOCShop 1.0 – Cross site request forgery
This exploit allows an attacker to change user information and passwords in the Joomla! extension JoomOCShop 1.0. The attacker can modify the user's firstname, lastname, email, telephone, and fax. Another exploit allows the attacker to change the user's password.
Mitigation:
Apply the latest patch or update to the Joomla! extension JoomOCShop. Implement proper input validation and authentication mechanisms to prevent CSRF attacks.