SQL Injection Vulnerability in Joomla OSDownloads by Joomla
CVE-2017-20259
Key Information:
- Vendor
Joomlashack
- Status
- Vendor
- CVE Published:
- 19 June 2026
Badges
What is CVE-2017-20259?
Joomla OSDownloads 1.7.4 is susceptible to an SQL injection vulnerability, enabling unauthorized attackers to inject and execute arbitrary SQL commands via the 'id' parameter. By constructing a specific GET request to index.php with parameters such as option=com_osdownloads&view=item&id=[SQL], attackers can potentially access sensitive information from the underlying database, including user credentials and configuration details, posing significant risks to the integrity and security of affected systems.
Affected Version(s)
OSDownloads 1.7.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
