JCH Optimize (com_jchoptimize) below 9.4.0 - Unauthenticated XSS and Page Cache Hit Counter Access Control Bypass, plus Admin CSRF and Open Redirect
JCH Optimize versions before 9.4.0 contain several flaws the vendor rates HIGH. A cross-site scripting issue let encoded characters in URLs, such as search query links, be decoded during optimization. The Page Cache hit counter exposed an unauthenticated com_ajax endpoint that took the component and model names from the request and called that model's hit() method, so any visitor could drive hit counters on content the page cache never served and read back exception messages. A jchbackend URL parameter let any visitor switch optimization off. Administrator tasks that change settings or files did not require a valid form token and administrator permissions (CSRF), the Mode Switcher and Utility tasks redirected to any URL passed in the return parameter, and image URLs and paths returned by the image optimization service were not validated or kept inside the site root. MEDIUM-rated fixes cover unescaped file and folder names in the Optimize Images tree and malformed Host headers influencing Page Cache and Capture Cache keys and file paths. Settings exports no longer include the Cloudflare API token or Redis password. No CVE has been assigned at the time of writing. Update to JCH Optimize 9.4.0 or later (the release notes require PHP 8.1 and Joomla 5.0, although the update feed still offers it to Joomla 4.4). There is no patched release for older branches.
Affected versions: < 9.4.0
Full advisory: our disclosure post