CVE-2017-20265
HIGH
7.1
CVSS 3.1
Description
Joomla! Component Flip Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wallid parameter. Attackers can send GET requests to index.php with the option=com_flipwall&task=click&wallid parameter containing SQL injection payloads to extract sensitive database information.
Metadata
Severity & Metrics
7.1
HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Pulseextensions | Flip Wall | — | 8.0 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-89 | cna | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
CVSS scores (2)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 7.1 | HIGH | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
| 7.1 | HIGH | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N |
References (4)
- ExploitDB-42524 https://www.exploit-db.com/exploits/42524
- Official Product Homepage http://pulseextensions.com/
- Product Reference https://extensions.joomla.org/extensions/extension/ads-a-affiliates/sponsors/flip-wall/
- VulnCheck Advisory: Joomla! Component Flip Wall 8.0 SQL Injection https://www.vulncheck.com/advisories/joomla-component-flip-wall-sql-injection