SQL Injection Vulnerability in Joomla com_hdwplayer by Joomla
CVE-2020-37218
Key Information:
- Vendor
HdWPlayer
- Status
- Vendor
- CVE Published:
- 13 May 2026
Badges
What is CVE-2020-37218?
The com_hdwplayer 4.2 component for Joomla is susceptible to an SQL injection flaw located in the search.php file. This vulnerability permits unauthenticated attackers to carry out arbitrary SQL queries through the hdwplayersearch parameter by crafting malicious POST requests. Exploitation of this weakness could lead to unauthorized exposure of sensitive data, including information from the hdwplayer_videos table, thereby compromising the integrity of the database and the broader Joomla installation.
Affected Version(s)
com_hdwplayer 4.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
