vendor:
Sexy Polling
by:
Wolfgang Hotwagner
9
CVSS
CRITICAL
SQL Injection
Unknown
CWE
Product Name: Sexy Polling
Affected Version From: All versions below 2.1.8
Affected Version To: 2.1.2007
Patch Exists: NO
Related CWE: Not yet
CPE: a:2glux:sexypolling
Platforms Tested: Debian Bullseye
2022
Joomla Plugin SexyPolling 2.1.7 – SQLi
In all versions below 2.1.8 of the Joomla plugin SexyPolling, an unauthenticated attacker can execute arbitrary SQL commands by sending crafted POST parameters to poll.php.
Mitigation:
Upgrade to version 2.1.8 or above.