vendor:
DT Register "Calendar & Event Registration"
by:
Elar Lang
7.5
CVSS
HIGH
SQL injection
89
CWE
Product Name: DT Register "Calendar & Event Registration"
Affected Version From: before 3.1.12 (Joomla 3.x) / 2.8.18 (Joomla 2.5)
Affected Version To: 3.1.12 (Joomla 3.x) / 2.8.18 (Joomla 2.5)
Patch Exists: YES
Related CWE: pending
CPE: a:dth_development:dt_register
Platforms Tested:
2016
SQL injection in Joomla extension DT Register
SQL injection in Joomla extension "DT Register" allows remote unauthenticated attacker to execute arbitrary SQL commands via the cat parameter.
Mitigation:
Upgrade to version 3.1.12 (Joomla 3.x) or 2.8.18 (Joomla 2.5)