Description
Joomla Extension - phoca.cz - Authorisation bypass through user-controlled key (IDOR) in Order View in Phoca Cart 5.0.0 - 6.1.8 - Phoca Cart's order-file download endpoint does not verify the download tokens it asks for. The d (download token) and o (order token) parameters are checked for non-emptiness only — they are never compared to the stored download_token / order_token values. As a result, any remote user (including a guest with no account at all) can download any customer's digital goods by enumerating sequential id values and supplying arbitrary non-empty tokens.
Published: 2026-10-05
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.phoca.cz/ cve-icon cve-icon
History

Tue, 06 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Phoca
Phoca phoca Cart Extension For Joomla
Vendors & Products Phoca
Phoca phoca Cart Extension For Joomla

Mon, 05 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - phoca.cz - Authorisation bypass through user-controlled key (IDOR) in Order View in Phoca Cart 5.0.0 - 6.1.8 - Phoca Cart's order-file download endpoint does not verify the download tokens it asks for. The d (download token) and o (order token) parameters are checked for non-emptiness only — they are never compared to the stored download_token / order_token values. As a result, any remote user (including a guest with no account at all) can download any customer's digital goods by enumerating sequential id values and supplying arbitrary non-empty tokens.
Title Joomla Extension - phoca.cz - Authorisation bypass through user-controlled key (IDOR) in Order View in Phoca Cart 5.0.0 - 6.1.8
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Phoca Phoca Cart Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-10-05T18:06:07.993Z

Reserved: 2026-09-29T16:46:15.044Z

Link: CVE-2026-102775

cve-icon Vulnrichment

Updated: 2026-10-05T16:29:37.651Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-05T16:17:04.317

Modified: 2026-10-06T15:05:34.080

Link: CVE-2026-102775

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:45:05Z

Weaknesses