GHSA-3r7g-gjfg-fgprHighCVSS 8.2
Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows...
🔗 CVE IDs covered (1)
📋 Description
Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the product_id parameter. Attackers can supply crafted SQL statements in GET requests to the brainy and alice views to extract sensitive database information.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2017-20261
- https://www.exploit-db.com/exploits/42552
- https://www.vulncheck.com/advisories/joomla-component-bargain-product-vm3-sql-injection
- https://www.weborange.eu
- https://www.weborange.eu/extensions/index.php/extensions-vm3/bargain-product-vm3-detail
- https://github.com/advisories/GHSA-3r7g-gjfg-fgpr