CVE-2026-102775
Joomla Extension - phoca.cz - Authorisation bypass through user-controlled key (IDOR) in Order View in Phoca Cart 5.0.0 - 6.1.8
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Joomla Extension - phoca.cz - Authorisation bypass through user-controlled key (IDOR) in Order View in Phoca Cart 5.0.0 - 6.1.8 - Phoca Cart's order-file download endpoint does not verify the download tokens it asks for. The d (download token) and o (order token) parameters are checked for non-emptiness only โ they are never compared to the stored download_token / order_token values. As a result, any remote user (including a guest with no account at all) can download any customer's digital goods by enumerating sequential id values and supplying arbitrary non-empty tokens.
| CWE | CWE-639 |
| Vendor | phoca.cz |
| Product | phoca cart extension for joomla |
| Published | Oct 5, 2026 |
| Last Updated | Oct 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for phoca.cz phoca cart extension for joomla
Be the first to know when new unknown vulnerabilities affecting phoca.cz phoca cart extension for joomla are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
phoca.cz / Phoca Cart extension for Joomla
5.0.0-6.1.8