SQL Injection Vulnerability in Joomla! Component PHP-Bridge by Joomla!
CVE-2017-20275
Key Information:
- Vendor
Henryschorradt
- Status
- Vendor
- CVE Published:
- 19 June 2026
Badges
What is CVE-2017-20275?
The PHP-Bridge component for Joomla! version 1.2.3 is susceptible to an SQL injection vulnerability. This flaw enables unauthenticated attackers to execute arbitrary SQL commands by exploiting the 'id' parameter in GET requests directed at index.php with specific options. By injecting malicious SQL code, attackers can potentially access sensitive database information, including the structure of tables and columns. Prompt mitigation is encouraged to protect against potential unauthorized data exposure.
Affected Version(s)
Bridge 1.2.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
