SQL Injection Vulnerability in Joomla LMS King Professional by Joomla
CVE-2017-20274
Key Information:
- Vendor
King-products
- Status
- Vendor
- CVE Published:
- 19 June 2026
Badges
What is CVE-2017-20274?
The Joomla LMS King Professional version 3.2.4.0 is susceptible to an SQL injection vulnerability that enables unauthenticated attackers to alter database queries. By injecting malicious SQL code through the cp_id parameter, an attacker can issue crafted GET requests to index.php, exploiting specific parameters such as option=com_lmsking, view=lmsking, layout=learningpath, and task=learningPath. This flaw allows unauthorized users to access and extract sensitive information from the database, posing significant security risks.
Affected Version(s)
LMS King Professional 3.2.4.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
