PT-2018-3604 · Open Source Matters · Joomla!
Published
2018-02-22
·
Updated
2021-01-30
·
CVE-2018-7318
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Joomla! CheckList component version 1.1.1
Description
The issue is related to SQL Injection in the CheckList component of Joomla!. This occurs due to inadequate protection against SQL query structure exploitation. An attacker can exploit this to execute arbitrary SQL commands remotely. The vulnerability can be exploited via the
title search, tag search, name search, description search, or filter order parameter.Recommendations
For Joomla! CheckList component version 1.1.1, consider disabling the component until a patch is available to prevent exploitation. Restrict access to the parameters
title search, tag search, name search, description search, and filter order to minimize the risk of SQL Injection attacks.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Joomla!