Junglewise Threat Intelligence

CVE-2018-25336: softPHP jCart for OpenCart CSRF in account management endpoints

CVE-2018-25336 · Severity: medium · CVSS 5.3 · Published 2026-05-17

Technologies: OpenCart. Vendors: OpenCart.

Executive brief

jCart is an e-commerce extension that integrates OpenCart features into Joomla websites. A security flaw allows an attacker to trick a logged-in user into unknowingly performing actions on the site, such as changing their own account password or email address. This could lead to unauthorized account takeovers or the modification of sensitive affiliate payment details.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the jCart extension for Joomla (specifically version 2.3.0.2 and potentially earlier). The application fails to implement sufficient anti-CSRF tokens on sensitive account management endpoints, including those for editing profile information, changing passwords, and updating affiliate details. An attacker can exploit this by hosting a malicious HTML form that automatically submits POST requests to these endpoints when visited by an authenticated victim. Successful exploitation allows an attacker to change user credentials or redirect affiliate payments without the user's knowledge.

Affected products

  • softPHP jCart for OpenCart 2.3.0.2 and earlier

Timeline

  • 2018-05-28: disclosed: Initial exploit proof-of-concept published on Exploit-DB
  • 2026-05-17: advisory: CVE published and NVD record created

References

Related threats