Executive brief
J2Store is an e-commerce extension for Joomla that enables online stores to sell products and manage inventory. The cart controller contains an open redirect vulnerability that allows attackers to craft malicious links appearing to come from a trusted shop domain, directing customers to phishing sites without authentication required. This can lead to credential theft and customer fraud.
Technical details
The vulnerability is an open redirect (CWE-601) in four task handlers of the J2Store cart controller across versions 1.0.0–3.3.20, 4.0.0–4.0.20, and 4.1.0–4.1.5. The handlers accept base64-encoded URLs from user input and redirect to them without validating the destination host. No authentication is required to exploit this. An attacker can craft a malicious URL that base64-encodes a phishing domain, and when a customer clicks the link (which appears to originate from the trusted shop domain), they are redirected to the attacker's site, facilitating credential harvesting and fraud. Patch availability is not noted in the advisory.
Affected products
- j2commerce.com J2Store 1.0.0–3.3.20, 4.0.0–4.0.20, 4.1.0–4.1.5
Timeline
- 2026-08-21: disclosed