Joomla JoomOCShop 1.0 Cross-Site Request Forgery
Vulnerability Description
Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML forms targeting account endpoints like /joomoc2/?route=account/edit and to modify user information or reset passwords without user consent.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-25337
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- L0RD or borna.nematzadeh123@gmail.com
References
Affected Vendor
Joomlaextensions
View all reports →