Joomla Survey Force Deluxe 3.2.4 SQL Injection via invite Parameter
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.8epss 0.4%
exploitation probability
0.4%top 63% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the invite parameter. Attackers can send GET requests to the component with crafted SQL payloads in the invite parameter to extract sensitive database information.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
Joomplace · Survey Force Deluxepublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/42606unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.