CVE-2015-7297: SQL Injection
Published Oct 29, 2015
·Updated
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7858.
Affected Software
15 affected components
Joomla Joomla\!=3.2.0
Joomla Joomla\!=3.2.1
Joomla Joomla\!=3.2.2
Joomla Joomla\!=3.2.3
Joomla Joomla\!=3.2.4
Joomla Joomla\!=3.3.0
Joomla Joomla\!=3.3.1
Joomla Joomla\!=3.3.2
Joomla Joomla\!=3.3.3
Joomla Joomla\!=3.3.4
Joomla Joomla\!=3.4.0
Joomla Joomla\!=3.4.1
Joomla Joomla\!=3.4.2
Joomla Joomla\!=3.4.3
Joomla Joomla\!=3.4.4
Event History
Oct 29, 2015
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7297?
CVE-2015-7297 has a medium severity rating due to the potential for remote SQL injection attacks.
2
How do I fix CVE-2015-7297?
To fix CVE-2015-7297, upgrade Joomla! to a version later than 3.4.4.
3
What versions of Joomla! are affected by CVE-2015-7297?
CVE-2015-7297 affects Joomla! versions from 3.2.0 to 3.4.4.
4
What types of attacks can CVE-2015-7297 facilitate?
CVE-2015-7297 can allow attackers to execute arbitrary SQL commands on the affected Joomla! installations.
5
Is CVE-2015-7297 related to any other vulnerabilities?
Yes, CVE-2015-7297 is a distinct vulnerability separate from CVE-2015-7858, yet both involve SQL injection in Joomla!