vendor:
Joomla
by:
Mateus Lino
9,8
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: Joomla
Affected Version From: 3.7.0
Affected Version To: 3.7.0
Patch Exists: YES
Related CWE: CVE-2017-8917
CPE: a:joomla:joomla:3.7.0
Other Scripts:
N/A
Tags: cve,cve2017,joomla,sqli
CVSS Metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Nuclei Metadata: {'max-request': 1, 'shodan-query': 'http.component:"Joomla"', 'verified': True, 'vendor': 'joomla', 'product': 'joomla\\!'}
Platforms Tested: Win, Kali Linux x64, Ubuntu, Manjaro and Arch Linux
2017
Joomla 3.7.0 – Sql Injection
Joomla! before 3.7.1 contains a SQL injection vulnerability. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.
Mitigation:
The vendor has released an update to address this vulnerability. Users are advised to upgrade to Joomla 3.7.1 or later.