First published: Wed Nov 26 2014(Updated: )
Multiple SQL injection vulnerabilities in the Kunena component before 3.0.6 for Joomla! allow remote authenticated users to execute arbitrary SQL commands via the index value in an array parameter, as demonstrated by the topics[] parameter in an unfavorite action to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kunena | <=3.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9102 is considered a medium severity vulnerability due to the potential for remote SQL command execution.
To fix CVE-2014-9102, update the Kunena component to version 3.0.6 or later.
CVE-2014-9102 affects users of Kunena versions prior to 3.0.6 integrated with Joomla!.
CVE-2014-9102 can facilitate SQL injection attacks, allowing malicious users to execute arbitrary SQL commands.
Using Kunena version 3.0.5 while CVE-2014-9102 is unpatched poses a security risk and should be avoided.