PT-2026-50958 · Joomla · Joomrecipe
CVE-2017-20277
·
Published
2026-06-19
·
Updated
2026-08-19
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
JoomRecipe version 1.0.4
Description
The JoomRecipe component for Joomla contains a blind SQL injection flaw. This allows attackers to inject SQL code via POST requests to the search endpoint using the
search author parameter. This can be used to extract database information through boolean-based blind SQL injection, a technique that determines data by asking the database true or false questions based on the application's response.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Joomrecipe