Vulnerability Description
Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the product_id parameter. Attackers can supply crafted SQL statements in GET requests to the brainy and alice views to extract sensitive database information.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Weborange | Bargain Product Vm3 | 1.0 |
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/42552ExploitVDB Entry
- https://www.vulncheck.com/advisories/joomla-component-bargain-product-vm3-sql-inThird Party Advisory
- https://www.weborange.eu/Broken Link
- https://www.weborange.eu/extensions/index.php/extensions-vm3/bargain-product-vm3Broken Link
FAQ
What is CVE-2017-20261?
CVE-2017-20261 is a vulnerability with a CVSS score of 8.2 (HIGH). Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the product...
How severe is CVE-2017-20261?
CVE-2017-20261 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-20261?
Check the references section above for vendor advisories and patch information. Affected products include: Weborange Bargain Product Vm3.