PT-2026-79437 · J2Store · J2Store

·

CVE-2026-67362

·

Published

2026-08-21

·

Updated

2026-08-21

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions J2Store versions 1.0.0 through 3.3.20 J2Store versions 4.0.0 through 4.0.20 J2Store versions 4.1.0 through 4.1.5
Description An open redirect exists in the cart controller where four task handlers accept a base64-encoded URL from user input and redirect to it without validating the destination host. This allows attackers to perform phishing attacks by leveraging the trusted domain of the shop. No authentication is required to exploit this issue.
Recommendations Update J2Store versions 1.0.0 through 3.3.20 to a version newer than 3.3.20. Update J2Store versions 4.0.0 through 4.0.20 to a version newer than 4.0.20. Update J2Store versions 4.1.0 through 4.1.5 to a version newer than 4.1.5.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67362

Affected Products

J2Store