PT-2026-79435 · J2Store · J2Store

·

CVE-2026-67360

·

Published

2026-08-21

·

Updated

2026-08-21

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions J2Store versions 1.0.0 through 3.3.20 J2Store versions 4.0.0 through 4.0.20 J2Store versions 4.1.0 through 4.1.5
Description An authenticated user can replicate orders from other customers by providing a different customer's order id. This allows the attacker to copy the cart contents and address data into their own session because the system validates the CSRF (Cross-Site Request Forgery) token but fails to verify if the user owns the requested order.
Recommendations Update J2Store versions 1.0.0 through 3.3.20 to a version newer than 3.3.20. Update J2Store versions 4.0.0 through 4.0.20 to a version newer than 4.0.20. Update J2Store versions 4.1.0 through 4.1.5 to a version newer than 4.1.5.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67360

Affected Products

J2Store