PT-2026-97517 · Joomla · Easy Store
CVE-2026-90905
·
Published
2026-09-23
·
Updated
2026-09-23
CVSS v4.0
7.2
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Easy Store versions 1.0.0 through 3.0.0
Description
The 'administrator/index.php?option=com easystore&task=appconfig.updateConfiguration' endpoint allows the update of core Joomla mail configuration in the
configuration.php file without verifying anti-CSRF tokens or administrative permissions. This allows a malicious site to silently modify the site's sender name and email address via forged requests from an administrator's browser. The issue involves the fromname and mailfrom variables.Recommendations
Update Easy Store to a version where
Session::checkToken('request') or Session::checkToken('post') is enforced and administrative authorization is verified via AccessControl::create()->canAdmin().Fix
Improper Access Control
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Easy Store