vendor:
Joomla Component J-CruisePortal
by:
Ihsan Sencan
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Joomla Component J-CruisePortal
Affected Version From: 6.0.4
Affected Version To: 6.0.7
Patch Exists: YES
Related CWE: N/A
CPE: a:cmsjunkie:joomla_component_j-cruiseportal
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WiN7_x64/KaLiLinuX_x64
2019
Joomla! Component J-CruisePortal 6.0.4 – SQL Injection
A SQL injection vulnerability exists in Joomla! Component J-CruisePortal 6.0.4, which allows an attacker to execute arbitrary SQL commands via the 'guest_adult' parameter in a 'cruises/cruises' POST request. This can be exploited to read, modify or delete data from the database.
Mitigation:
The vendor has released an update to address this vulnerability. Users are advised to update to the latest version.