vendor:
Google Map Landkarten
by:
Ihsan Sencan
9.8
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: Google Map Landkarten
Affected Version From: <= 4.2.3
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2018-6396
CPE: a:joomla:google_map_landkarten
Platforms Tested: Windows 7 x64, Kali Linux x64
2018
Joomla! Component Google Map Landkarten <= 4.2.3 - SQL Injection
The Joomla! Component Google Map Landkarten version 4.2.3 and below is vulnerable to SQL Injection. An attacker can exploit this vulnerability by injecting SQL code into the 'cid' parameter in the 'index.php' file. This can lead to unauthorized access to the database and potentially sensitive information leakage.
Mitigation:
The vendor has released a patch to address this vulnerability. Users are advised to update to the latest version of the Google Map Landkarten component (version > 4.2.3). Additionally, it is recommended to apply proper input validation and sanitization techniques to prevent SQL injection attacks.