SQL Injection Flaw in Joomla! Component Price Alert from Joomla!
CVE-2017-20260
Key Information:
- Vendor
Weborange
- Status
- Vendor
- CVE Published:
- 19 June 2026
Badges
What is CVE-2017-20260?
The Joomla! Component Price Alert version 3.0.2 is susceptible to an SQL injection vulnerability that can be exploited by unauthenticated attackers. By manipulating the product_id parameter in requests sent to the subscribeajax view, attackers can inject malicious SQL code. This could allow them to run arbitrary SQL queries, potentially exposing sensitive information stored in the database, including user credentials and configuration details. The exploitation of this vulnerability poses a significant risk to data integrity and confidentiality for Joomla! users.
Affected Version(s)
Price Alert 3.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
