vendor:
Joomla JE Story submit
by:
L0rd CrusAd3r
8,8
CVSS
HIGH
SQLi Vulnerability
89
CWE
Product Name: Joomla JE Story submit
Affected Version From: 1.4
Affected Version To: 1.4
Patch Exists: Yes
Related CWE: N/A
CPE: a:joomlaextensions:joomla_je_story_submit
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Joomla JE Story submit SQL Injection
A SQL injection vulnerability exists in Joomla JE Story submit component version 1.4. The vulnerability allows an attacker to execute arbitrary SQL commands on the vulnerable system. The vulnerability is due to insufficient sanitization of user-supplied input in the 'view' parameter of the 'component/jesubmit/' URL. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable system. Successful exploitation of this vulnerability can result in unauthorized access to sensitive information, modification of data, and other malicious activities.
Mitigation:
The vendor has released an update to address this vulnerability. Users are advised to update to the latest version of Joomla JE Story submit component.