-
CVE-2026-75953
- EPSS 0.15%
- Veröffentlicht 19.08.2026 14:45:26
- Zuletzt bearbeitet 19.08.2026 15:18:09
- CVE-Watchlists
- Unerledigt
Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3
Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitrary address.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellercmsjunkie.com
≫
Produkt
J-BusinessDirectory extension for Joomla
Default Statusunaffected
Version
1.0.0-6.2.2
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.047 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
CWE-201 Insertion of Sensitive Information Into Sent Data
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.