PT-2026-40619 · Hdwplayer · Com Hdwplayer

Qw3Rtyty

·

Published

2026-05-13

·

Updated

2026-05-13

·

CVE-2020-37218

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Joomla com hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hdwplayersearch parameter. Attackers can submit POST requests with crafted SQL payloads in the hdwplayersearch parameter to extract sensitive database information from the hdwplayer videos table.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2020-37218

Affected Products

Com Hdwplayer