vendor:
J-BusinessDirectory
by:
Ihsan Sencan
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: J-BusinessDirectory
Affected Version From: 4.9.7
Affected Version To: 4.9.7
Patch Exists: YES
Related CWE: N/A
CPE: a:cmsjunkie:j-businessdirectory:4.9.7
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WiN7_x64/KaLiLinuX_x64
2019
Joomla! Component J-BusinessDirectory 4.9.7 – SQL Injection
A SQL injection vulnerability exists in Joomla! Component J-BusinessDirectory 4.9.7. An attacker can send a malicious HTTP request to the vulnerable server and execute arbitrary SQL commands in the back-end database.
Mitigation:
The vendor has released an update to address this vulnerability. Users are advised to update to the latest version.