First published: Wed Dec 14 2011(Updated: )
SQL injection vulnerability in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a fnd_home action to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
joomlaextensions Com hmcommunity | <=1.0 | |
Joomla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4808 is considered a high-severity vulnerability due to its potential for SQL injection, allowing attackers to execute arbitrary SQL commands.
To fix CVE-2011-4808, you should update the HM Community component to version 1.01 or later.
CVE-2011-4808 affects versions of the HM Community component prior to 1.01 when used with Joomla!.
If CVE-2011-4808 is exploited, attackers could gain unauthorized access to the database, allowing for data manipulation or extraction.
Yes, there is a patch available that can be obtained by updating the HM Community component to the latest version.