SQL Injection Vulnerability in Joomla! Component Ajax Quiz by Joomla
CVE-2017-20262
Key Information:
Badges
What is CVE-2017-20262?
The Joomla! Component Ajax Quiz 1.8 is susceptible to an SQL injection vulnerability. This security issue enables unauthorized attackers to execute arbitrary SQL queries by manipulating the 'cid' parameter in GET requests. By exploiting the vulnerability, an attacker can leverage the 'option=com_ajaxquiz' and 'view=ajaxquiz' parameters to gain access to sensitive information within the database, such as table names and column structures. If left unaddressed, this vulnerability poses a significant risk to data privacy and integrity.
Affected Version(s)
Ajax Quiz 1.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
