CVE-2026-102775
Received Received - Intake

Phoca Cart Authorisation Bypass via IDOR in Order View

Vulnerability report for CVE-2026-102775, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Joomla! Project

Description

Joomla Extension - phoca.cz - Authorisation bypass through user-controlled key (IDOR) in Order View in Phoca Cart 5.0.0 - 6.1.8 - Phoca Cart's order-file download endpoint does not verify the download tokens it asks for. The d (download token) and o (order token) parameters are checked for non-emptiness only β€” they are never compared to the stored download_token / order_token values. As a result, any remote user (including a guest with no account at all) can download any customer's digital goods by enumerating sequential id values and supplying arbitrary non-empty tokens.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
phoca.cz Phoca Cart extension for Joomla 5.0.0-6.1.8

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an Insecure Direct Object Reference (IDOR) vulnerability in the Phoca Cart Joomla extension versions 5.0.0 to 6.1.8. It allows unauthorised users to bypass authorisation and download any customer's digital goods by manipulating download and order tokens. The system fails to verify if the provided tokens match stored values, only checking if they are non-empty.

Detection Guidance

Check Phoca Cart versions 5.0.0 to 6.1.8 for exposed order-file download endpoints. Test by accessing URLs like /index.php?option=com_phocacart&view=order&task=download&d=1&o=1 with sequential IDs to see if unauthorized downloads are possible.

Impact Analysis

Attackers can access sensitive digital products without permission, leading to financial loss, reputational damage, or data breaches. Even unauthenticated users can exploit this by guessing order IDs and supplying arbitrary tokens.

Compliance Impact

This vulnerability could violate GDPR by exposing personal data or HIPAA by allowing unauthorised access to protected health information. It undermines data integrity and confidentiality requirements in these regulations.

Mitigation Strategies

Update Phoca Cart to the latest version beyond 6.1.8. If an update is unavailable, disable the order-file download feature or restrict access to authenticated users only. Review server logs for suspicious download attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102775. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart