CVE-2018-17254
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 83%
from disclosure to weapon0 days
Published on NVDSep 20
1st PoCSep 17
VulnCheck+2551d
exploitation probability
83%top 1% of all CVEs
observed exploitation
yesVulnCheck
8 public exploit(s)
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
Affected products
n/a · n/apublic PoCs found — 8✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/45423exploitdbwww.exploit-db.com/exploits/49627unverifiedgithubgithub.com/Nickguitar/Joomla-JCK-Editor-6.4.4-SQL-Injection★ 10githubgithub.com/MataKucing-OFC/CVE-2018-17254★ 0vulncheckvulncheck.com/xdb/5bb757ccb3aaunverifiedcve_referencewww.exploit-db.com/exploits/45423/unverifiedvulncheckvulncheck.com/xdb/8ed7b2c9bb2aunverifiedcve_referencepacketstormsecurity.com/files/161683/Joomla-JCK-Editor-6.4.4-SQL-Injection.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.