PT-2017-17855 · Joomla+1 · Smart Related Articles+1
Published
2017-04-13
·
Updated
2019-10-03
·
CVE-2017-7627
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Joomla "Smart related articles" extension version 1.1
Description
The issue concerns a missing JEXEC check in the dialog.php file of the "Smart related articles" extension for Joomla, allowing direct requests to this file.
Recommendations
For version 1.1 of the "Smart related articles" extension, consider adding a JEXEC check to the dialog.php file to prevent direct requests until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Joomla!
Smart Related Articles