The J2Store plugin before 3.3.13 for Joomla! allows a SQL injection attack by a trusted store manager.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13996
Reference (s):
- https://www.j2store.org/download-j2store/j2store-v3-3-3-13.html
- https://www.j2store.org/resources/change-log.html

