GHSA-f3w3-4pxg-f2qcHighCVSS 8.2
Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows...
🔗 CVE IDs covered (1)
📋 Description
Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the ajaxaction.flag_question task. Attackers can inject malicious SQL code via the stu_quiz_id or flag_quest parameters to manipulate database queries and extract sensitive information.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2017-20257
- https://extensions.joomla.org/extensions/extension/living/education-a-culture/quiz-deluxe
- https://www.exploit-db.com/exploits/42589
- https://www.vulncheck.com/advisories/joomla-component-quiz-deluxe-sql-injection
- http://joomplace.com
- https://github.com/advisories/GHSA-f3w3-4pxg-f2qc