PT-2018-3604 · Open Source Matters · Joomla!

Published

2018-02-22

·

Updated

2021-01-30

·

CVE-2018-7318

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Joomla! CheckList component version 1.1.1
Description The issue is related to SQL Injection in the CheckList component of Joomla!. This occurs due to inadequate protection against SQL query structure exploitation. An attacker can exploit this to execute arbitrary SQL commands remotely. The vulnerability can be exploited via the title search, tag search, name search, description search, or filter order parameter.
Recommendations For Joomla! CheckList component version 1.1.1, consider disabling the component until a patch is available to prevent exploitation. Restrict access to the parameters title search, tag search, name search, description search, and filter order to minimize the risk of SQL Injection attacks.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01066
CVE-2018-7318

Affected Products

Joomla!