Vulnerability Description
Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname parameter. Attackers can send GET requests to index.php with option=com_nge&view=config and inject malicious SQL code in the plname parameter to extract sensitive database information.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nextgeneditor | Nextgen Editor | 2.1.0 |
Related Weaknesses (CWE)
References
- https://extensions.joomla.org/extension/nextgen-editor/Product
- https://www.exploit-db.com/exploits/43365ExploitVDB Entry
- https://www.vulncheck.com/advisories/joomla-nextgen-editor-sql-injection-via-plnThird Party Advisory
FAQ
What is CVE-2017-20252?
CVE-2017-20252 is a vulnerability with a CVSS score of 8.2 (HIGH). Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname parameter. Attackers can send GET request...
How severe is CVE-2017-20252?
CVE-2017-20252 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-20252?
Check the references section above for vendor advisories and patch information. Affected products include: Nextgeneditor Nextgen Editor.