vendor:
SpiderCalendar
by:
Red-D3v1L
7,8
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: SpiderCalendar
Affected Version From: 1.0
Affected Version To: 1.2
Patch Exists: YES
Related CWE: CVE-2020-12345
CPE: a:joomla:spidercalendar
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2020
Joomla Component (com_spidercalendar) Blind SQL Injection Vulnerability
A Blind SQL Injection vulnerability was discovered in the Joomla component com_spidercalendar. The vulnerability is caused due to the lack of input validation in the 'date' parameter of the 'index.php' script when handling a 'GET' request. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
Mitigation:
Upgrade to the latest version of the Joomla component com_spidercalendar.