Security Advisory

CVE-2026-75950

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-19 14:40:08
Last updated 2026-08-21 19:15:24
Assigner Joomla
CVSS score 6.9
State PUBLISHED

Description

Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already had an owner. 6.2.3 binds the action to the authenticated user and only allows unowned listings.