Eight tasks which the buttons of the back-end lists call did not check Joomla’s form token: setting the default payment method, shipping method, image type set, order status and watermark; putting an event into the shop or taking it out (In shop); choosing the main image of an event and whether an image is shown only as the main image; and sorting the images of an event. A prepared page on another web site could therefore trigger them in the name of a logged in administrator and change those settings and flags. Nothing can be deleted or read this way, and orders are not affected.
- Needed: no account. The victim is logged in to the back end with the permission Manage of Event Gallery and opens a prepared page.
- Affected: all versions before 6.6.0, 4.3.3 included.
- Fixed in: 6.6.0. All eight tasks need the form token; the star and the table icon of the image list submit the list form instead of following a link.
-
Severity: CVSS 4.0 5.1 (
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N), CWE-352. - CVE: CVE-2026-102776.
All prices include VAT. The gross price will vary depending on the selected shipping country.