vendor:
J2Store Plugin for Joomla!
by:
Andrei Conache
9.8
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: J2Store Plugin for Joomla!
Affected Version From: 3.x
Affected Version To: 3.3.6
Patch Exists: YES
Related CWE: CVE-2019-9184
CPE: 2.3:a:j2store:j2store:3.3.6
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2019
J2Store Plugin for Joomla! < 3.3.6 - SQL Injection
J2Store is the most popular shopping/e-commerce extension for Joomla!. The SQL Injection found allows any visitor to run arbitrary queries on the website.
Mitigation:
Update to 3.3.7 or later.