SQL Injection Vulnerability in Joomla Ultimate Property Listing by Joomla
CVE-2017-20272
Key Information:
- Vendor
Faboba
- Vendor
- CVE Published:
- 19 June 2026
Badges
What is CVE-2017-20272?
The Joomla Ultimate Property Listing version 1.0.2 is susceptible to an SQL injection vulnerability that enables unauthenticated attackers to execute arbitrary SQL commands. By manipulating the sf_selectuser_id parameter in the request, attackers can send specially crafted GET requests to index.php with the options set to com_upl and view to propertylisting. This exploitation can lead to unauthorized access to sensitive database information, such as table names and column structures, posing a significant risk to the integrity of the web application and its data.
Affected Version(s)
Ultimate Property Listing 1.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
