PT-2026-79438 · J2Store · J2Store
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
J2Store versions 1.0.0 through 3.3.20
J2Store versions 4.0.0 through 4.0.20
J2Store versions 4.1.0 through 4.1.5
Description
Stored Cross-Site Scripting (XSS) exists in the guest checkout billing address fields. An unauthenticated attacker can store unsanitized HTML in fields such as
billing first name by exploiting a filter bypass in the Input::getArray() function combined with the PHP variables order=EGPCS configuration, where cookies override POST data in the $ REQUEST superglobal.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
J2Store