Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Phoenixx

#19684of 53,622
13.3Total CVSS
Vulnerabilities · 2
Medium
2
PT-2017-7260
6.5
2017-10-18
Open Source Matters · Joomla! · CVE-2015-7714
**Name of the Vulnerable Software and Affected Versions** com rpl component versions prior to 8.9.5 for Joomla! **Description** The issue allows remote administrators to execute arbitrary SQL commands. This can be achieved via various parameters in the administrator/index.php endpoint, including `id`, `copy field` in a data copy action, `pshow` in an update field action, `css`, `tip`, `cat id`, `text search`, `plisting`, or `pwizard`. **Recommendations** For com rpl component versions prior to 8.9.5, update to version 8.9.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the administrator/index.php endpoint and limiting the use of the vulnerable parameters until the update is applied.
PT-2017-7261
6.8
2017-10-18
Joomla · Realtyna Rpl · CVE-2015-7715
**Name of the Vulnerable Software and Affected Versions** Realtyna RPL (com rpl) component versions prior to 8.9.5 for Joomla! **Description** A cross-site request forgery (CSRF) issue allows remote attackers to hijack the authentication of administrators for requests that add a user via an `add user` action to "administrator/index.php". **Recommendations** For versions prior to 8.9.5, update to version 8.9.5 or later to resolve the issue.