PT-2023-10808 · Unknown · Joomgallery

Published

2023-01-06

·

Updated

2024-05-17

·

CVE-2018-25067

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JoomGallery versions up to 3.3.3
Description A critical issue was found in JoomGallery, affecting an unknown part of the file administrator/components/com joomgallery/views/config/tmpl/default.php of the component Image Sort Handler. The manipulation leads to sql injection.
Recommendations For JoomGallery versions up to 3.3.3, upgrade to version 3.3.4 to address this issue.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2018-25067

Affected Products

Joomgallery