PT-2026-50958 · Joomla · Joomrecipe

CVE-2017-20277

·

Published

2026-06-19

·

Updated

2026-08-19

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions JoomRecipe version 1.0.4
Description The JoomRecipe component for Joomla contains a blind SQL injection flaw. This allows attackers to inject SQL code via POST requests to the search endpoint using the search author parameter. This can be used to extract database information through boolean-based blind SQL injection, a technique that determines data by asking the database true or false questions based on the application's response.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-20277

Affected Products

Joomrecipe