CVE-2018-25337

Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML forms targeting account endpoints like /joomoc2/?route=account/edit and to modify user information or reset passwords without user consent.
Configurations

No configuration.

History

17 May 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-17 13:16

Updated : 2026-06-17 01:55


NVD link : CVE-2018-25337

Mitre link : CVE-2018-25337

CVE.ORG link : CVE-2018-25337


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)