PT-2026-41563 · Unknown · Joomocshop

Published

2026-05-17

·

Updated

2026-05-17

·

CVE-2018-25337

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions JoomOCShop version 1.0
Description A cross-site request forgery issue allows attackers to perform unauthorized actions on behalf of authenticated users. By crafting malicious HTML forms targeting the '/joomoc2/?route=account/edit' endpoint, attackers can modify user information or reset passwords without consent.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-25337

Affected Products

Joomocshop