GHSA-f3w3-4pxg-f2qcHighCVSS 8.2

Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows...

Published
June 19, 2026
Last Modified
June 19, 2026

🔗 CVE IDs covered (1)

📋 Description

Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the ajaxaction.flag_question task. Attackers can inject malicious SQL code via the stu_quiz_id or flag_quest parameters to manipulate database queries and extract sensitive information.

🔗 References (6)