Vulnerability Description
Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the ajaxaction.flag_question task. Attackers can inject malicious SQL code via the stu_quiz_id or flag_quest parameters to manipulate database queries and extract sensitive information.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Joomplace | Quiz Deluxe | 3.7.4 |
Related Weaknesses (CWE)
References
- http://joomplace.com/Product
- https://extensions.joomla.org/extensions/extension/living/education-a-culture/quProduct
- https://www.exploit-db.com/exploits/42589ExploitVDB Entry
- https://www.vulncheck.com/advisories/joomla-component-quiz-deluxe-sql-injectionThird Party Advisory
FAQ
What is CVE-2017-20257?
CVE-2017-20257 is a vulnerability with a CVSS score of 8.2 (HIGH). Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the ajaxaction.flag_question task. Attackers...
How severe is CVE-2017-20257?
CVE-2017-20257 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-20257?
Check the references section above for vendor advisories and patch information. Affected products include: Joomplace Quiz Deluxe.