An authenticated attacker with privileges to manage Finder filters can inject SQL via improperly built filter clauses in com_finder. The Indexer used an attacker-controllable string as the key in the filter map, allowing downstream code to be tricked into executing arbitrary SQL against the Joomla database.

This vulnerability affects the following application versions:

  • Joomla 5.4.2
  • Joomla 5.4.3
  • Joomla 5.4.4
  • Joomla 5.4.5
  • Joomla 6.0.2
  • Joomla 6.0.3
  • Joomla 6.0.4
  • Joomla 6.1.0

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *