CVE-2020-35613SQL Injection in Joomla !

CWE-89SQL Injection3 documents3 sources
Severity
9.8CRITICALNVD
EPSS
0.5%
top 33.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 28
Latest updateMay 24

Description

An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injection vulnerability in the backend user list.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDjoomla/joomla_!3.0.03.9.22
CVEListV5joomla!_project/joomla!_cms3.0.0-3.9.22

🔴Vulnerability Details

2
GHSA
GHSA-c94j-m65h-vm53: An issue was discovered in Joomla! 32022-05-24
CVEList
[20201104] - Core - SQL injection in com_users list view2020-12-28