9.8
CVSSv3

CVE-2018-17377

Published: 28/09/2018 Updated: 14/11/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

extensiondeveloper questions 1.4.3

Exploits

# # # # # # Exploit Title: Joomla! Component Questions 143 - SQL Injection # Dork: N/A # Date: 2018-09-24 # Vendor Homepage: extensiondevelopercom/ # Software Link: extensionsjoomlaorg/extensions/extension/communication/question-a-answers/questions/ # Version: 143 # Category: Webapps # Tested on: WiN7_x64/KaLiLinuX_x64 # CVE: ...
Joomla! Questions component version 143 suffers from a remote SQL injection vulnerability ...