Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

EasyStore 3.0.1 fixes seven Joomla security flaws

JoomShaper has released EasyStore 3.0.1 for Joomla, fixing seven security vulnerabilities that affected every version below 3.0.1, including 2.0.1 and 3.0.0.

The disclosure from mySites.guru says the most serious issue allowed any visitor to retrieve a guest shopper’s name, shipping address and phone number by supplying an email address. No login was required. The remaining issues involved SQL injection in two administrator endpoints, missing CSRF protections in administrative functions, an unprotected configuration update, a permission check that always allowed editing, and a CSRF flaw that could allow reviews to be posted in a logged-in customer’s name.

mySites.guru rated the customer lookup and both SQL injection flaws High under provisional CVSS 4.0 scores. The other four issues were rated Medium. Seven CVE identifiers had been reserved, but the advisory says the CVE records were not yet published when it was written.

JoomShaper fixed the flaws in EasyStore 3.0.1 for both Free and Pro editions. The advisory reports no active exploitation, but the vulnerabilities were exploitable under the conditions described.

  • Update all EasyStore installations to 3.0.1 or later.
  • Review Joomla mail settings, administrator accounts and unexpected site changes after updating.
  • Consider potential exposure of guest shipping data on installations running an affected version.

Originally reported by mySites.guru.