PT-2018-3604 · Open Source Matters · Joomla!
Publicado
2018-02-22
·
Atualizado
2021-01-30
·
CVE-2018-7318
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Joomla! CheckList component version 1.1.1
Description
The issue is related to SQL Injection in the CheckList component of Joomla!. This occurs due to inadequate protection against SQL query structure exploitation. An attacker can exploit this to execute arbitrary SQL commands remotely. The vulnerability can be exploited via the
title search, tag search, name search, description search, or filter order parameter.Recommendations
For Joomla! CheckList component version 1.1.1, consider disabling the component until a patch is available to prevent exploitation. Restrict access to the parameters
title search, tag search, name search, description search, and filter order to minimize the risk of SQL Injection attacks.Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Joomla!