Security
Phoca Cart flaw exposed customers’ paid downloads
A high-severity IDOR in Phoca Cart allowed unauthenticated visitors to download digital products purchased by other customers, according to mySites.guru.
The affected extension is Phoca Cart, developed by Phoca. The issue affects versions before 6.1.9, including 6.1.8, and stems from an authorisation check that accepted supplied tokens without verifying them against the order records. mySites.guru rates the vulnerability 8.7 High on CVSS 4.0.
No CVE identifier has been assigned to this issue. The research describes the flaw as exploitable over the internet without an account, although mySites.guru says its assessment was based on code review and did not involve requesting files from a live site or publishing a working request.
- Joomla 6 administrators should update to Phoca Cart
6.1.9. - Joomla 5 sites should install the
6.1.9package manually; the updater may not offer it. - Joomla 3 and 4 have no fixed release listed. Administrators should plan a Joomla migration and treat downloadable files as potentially exposed.
Phoca Cart releases 5.2.4, 4.0.13 and 3.5.8 remain affected on their respective Joomla branches.
Originally reported by mySites.guru.