PT-2018-3604 · Open Source Matters · Joomla!

Publicado

2018-02-22

·

Atualizado

2021-01-30

·

CVE-2018-7318

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Joomla! CheckList component version 1.1.1
Description The issue is related to SQL Injection in the CheckList component of Joomla!. This occurs due to inadequate protection against SQL query structure exploitation. An attacker can exploit this to execute arbitrary SQL commands remotely. The vulnerability can be exploited via the title search, tag search, name search, description search, or filter order parameter.
Recommendations For Joomla! CheckList component version 1.1.1, consider disabling the component until a patch is available to prevent exploitation. Restrict access to the parameters title search, tag search, name search, description search, and filter order to minimize the risk of SQL Injection attacks.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2021-01066
CVE-2018-7318

Produtos afetados

Joomla!