PT-2026-97517 · Joomla · Easy Store

CVE-2026-90905

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v4.0

7.2

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Easy Store versions 1.0.0 through 3.0.0
Description The 'administrator/index.php?option=com easystore&task=appconfig.updateConfiguration' endpoint allows the update of core Joomla mail configuration in the configuration.php file without verifying anti-CSRF tokens or administrative permissions. This allows a malicious site to silently modify the site's sender name and email address via forged requests from an administrator's browser. The issue involves the fromname and mailfrom variables.
Recommendations Update Easy Store to a version where Session::checkToken('request') or Session::checkToken('post') is enforced and administrative authorization is verified via AccessControl::create()->canAdmin().

Fix

Improper Access Control

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90905

Affected Products

Easy Store