Vulnerability Description
The VirtueMart com_virtuemart component 3.0.14 for Joomla! allows SQL injection by remote authenticated administrators via the virtuemart_paymentmethod_id or virtuemart_shipmentmethod_id parameter to administrator/index.php.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Virtuemart | Virtuemart | 3.0.14 |
Related Weaknesses (CWE)
References
- http://code610.blogspot.com/2016/08/testing-sql-injections-in-comvirtuemart.htmlExploitThird Party Advisory
- http://www.securityfocus.com/bid/98753Third Party AdvisoryVDB Entry
- http://code610.blogspot.com/2016/08/testing-sql-injections-in-comvirtuemart.htmlExploitThird Party Advisory
- http://www.securityfocus.com/bid/98753Third Party AdvisoryVDB Entry
FAQ
What is CVE-2016-10379?
CVE-2016-10379 is a vulnerability with a CVSS score of 7.2 (HIGH). The VirtueMart com_virtuemart component 3.0.14 for Joomla! allows SQL injection by remote authenticated administrators via the virtuemart_paymentmethod_id or virtuemart_shipmentmethod_id parameter to ...
How severe is CVE-2016-10379?
CVE-2016-10379 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-10379?
Check the references section above for vendor advisories and patch information. Affected products include: Virtuemart Virtuemart.