SQL Injection Vulnerability in SIMGenealogy Component for Joomla!
CVE-2017-20276
Key Information:
- Vendor
Simbunch
- Status
- Vendor
- CVE Published:
- 19 June 2026
Badges
What is CVE-2017-20276?
The SIMGenealogy component for Joomla! version 2.1.5 is susceptible to an SQL injection vulnerability. Malicious actors can exploit this flaw by sending crafted GET requests to index.php, allowing them to manipulate database queries through the vulnerable type parameter. This could lead to unauthorized access to sensitive information stored in the database, posing significant risks to website integrity and user data privacy. Ensuring your Joomla! installations are updated and patched against such vulnerabilities is crucial for maintaining a secure web environment.
Affected Version(s)
SIMGenealogy 2.1.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
