PT-2018-17093 · Joomla · Com Adagency

CVE-2018-5696

·

Published

2018-01-14

·

Updated

2022-10-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: com adagency plugin version 6.0.9 for Joomla!
Description: The issue allows SQL injection via the advertiser status and status select parameters to "index.php". This can potentially lead to unauthorized access to sensitive data.
Recommendations: For com adagency plugin version 6.0.9, consider restricting access to the vulnerable parameters advertiser status and status select in the "index.php" endpoint until a patch is available. Avoid using these parameters to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-5696

Affected Products

Com Adagency