SB2018031303 - SQL injection in Joomla!
Published: March 13, 2018 Updated: January 4, 2019
Security Bulletin ID
SB2018031303
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) SQL injection (CVE-ID: CVE-2018-8045)
The vulnerability allows a remote attacker to execute arbitrary SQL commands in web application database.The vulnerability exists due to insufficient filtration of user-supplied data in User Notes list view. A remote attacker can execute arbitrary SQL commands in web application database.
Successful exploitation of the vulnerability may lead to website compromise.
Remediation
Install update from vendor's website.