PT-2026-103298 · Joomla · Jctables
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y |
Name of the Vulnerable Software and Affected Versions
JCTables version 1.21.1
Description
An unauthenticated SQL injection exists in the front-end CRUD API controller. The component fails to perform Joomla token validation and authentication checks on any task. Table names, column names, and values are taken directly from request parameters and concatenated into SQL queries, enabling unauthorized read and write operations.
Recommendations
Update JCTables to a version newer than 1.21.1.
Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jctables