9.8
CVSSv3

CVE-2018-7313

Published: 22/02/2018 Updated: 05/03/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

cwjoomla cw tags 2.0.6

Exploits

# # # # # Exploit Title: Joomla! Component CW Tags 206 - SQL Injection # Dork: N/A # Date: 22022018 # Vendor Homepage: wwwcwjoomlacom/ # Software Link: extensionsjoomlaorg/extensions/extension/search-a-indexing/tags-a-clouds/cw-tags/ # Version: 206 # Category: Webapps # Tested on: WiN7_x64/KaLiLinuX_x64 # CVE: CVE-2018-7313 ...
Joomla! CW Tags component version 206 suffers from a remote SQL injection vulnerability ...