PT-2020-16184 · Joomla · Pago Commerce

Published

2020-09-18

·

Updated

2020-09-24

·

CVE-2020-25751

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions paGO Commerce plugin version 2.5.9.0 for Joomla!
Description The issue allows SQL Injection via the "administrator/index.php?option=com pago&view=comments" API endpoint, specifically through the filter published parameter.
Recommendations For paGO Commerce plugin version 2.5.9.0, avoid using the filter published parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25751

Affected Products

Pago Commerce