vendor:
com_jdirectory
by:
Caddy-Dz
7.5
CVSS
HIGH
SQL Injection
Not mentioned
CWE
Product Name: com_jdirectory
Affected Version From: Not mentioned
Affected Version To: Not mentioned
Patch Exists: NO
Related CWE: Not mentioned
CPE: Not mentioned
Platforms Tested: Windows 7 Edition Intégral (French)
Not mentioned
Joomla Component com_jdirectory SQL Injection Vulnerability
The Joomla Component com_jdirectory is vulnerable to SQL Injection. An attacker can inject malicious SQL queries through the 'contentid' parameter in the URL, which can lead to unauthorized access or data manipulation in the database.
Mitigation:
Update the Joomla Component com_jdirectory to the latest version or apply the vendor's patch if available. Validate and sanitize user input before executing SQL queries.