CVE-2017-20252: Joomla NextGen Editor 2.1.0 SQL Injection via plname Parameter
Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname parameter. Attackers can send GET requests to index.php with option=comnge&view=config and inject malicious SQL code in the plname parameter to extract sensitive database information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-20252?
CVE-2017-20252 has a high severity score of 8.2.
How do I fix CVE-2017-20252?
To fix CVE-2017-20252, it is recommended to update Joomla NextGen Editor to a patched version that addresses the SQL injection vulnerability.
What type of vulnerability is CVE-2017-20252?
CVE-2017-20252 is classified as an SQL injection vulnerability.
Who is affected by CVE-2017-20252?
CVE-2017-20252 affects instances of Joomla NextGen Editor version 2.1.0.
What can attackers do with CVE-2017-20252?
Attackers can exploit CVE-2017-20252 to execute arbitrary SQL commands via the plname parameter.