CVE-2017-20257: Joomla! Component Quiz Deluxe 3.7.4 SQL Injection

Published Jun 19, 2026
·
Updated

Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the ajaxaction.flagquestion task. Attackers can inject malicious SQL code via the stuquizid or flagquest parameters to manipulate database queries and extract sensitive information.

Affected Software

2 affected components
Joomla Quiz Deluxe=3.7.4
Joomplace Quiz Deluxe Joomla\!=3.7.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Joomla! Component Quiz Deluxe 3.7.4 from your environment.

    Uninstall the Quiz Deluxe component (version 3.7.4) if it is not required, or disable the component in Joomla until a vendor-supplied fix is available.

  2. Configuration

    Disable or block the ajaxaction.flag_question task in the component configuration or by modifying the component code to prevent processing of that AJAX task (prevent unauthenticated access to stu_quiz_id and flag_quest parameters).

    Joomla! Quiz Deluxe component ajaxaction.flag_question = disabled
  3. Compensating control

    Apply WAF rules or web server access controls to block or sanitize requests to the Quiz Deluxe AJAX endpoint (specifically requests invoking ajaxaction.flag_question and requests containing stu_quiz_id or flag_quest parameters). Restrict access to the component's AJAX endpoints to trusted IPs where possible.

  4. Operational

    Inspect application and database logs for signs of exploitation or data exfiltration related to the ajaxaction.flag_question task; perform forensic analysis and rotate any credentials or secrets that may have been exposed if compromise is suspected.

Event History

Jun 19, 2026
CVE Published
via MITRE·03:34 PM
Data Sourced
via MITRE·03:34 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2017-20257?

The severity of CVE-2017-20257 is rated high with a score of 8.8.

2

What does CVE-2017-20257 exploit?

CVE-2017-20257 exploits an SQL injection vulnerability in the Joomla! Component Quiz Deluxe 3.7.4.

3

How do I fix CVE-2017-20257?

To fix CVE-2017-20257, update Joomla! Component Quiz Deluxe to a patched version that addresses the SQL injection issue.

4

What kind of attackers can exploit CVE-2017-20257?

CVE-2017-20257 can be exploited by unauthenticated attackers.

5

What parameters are affected by CVE-2017-20257?

CVE-2017-20257 is affected by the stu_quiz_id and flag_quest parameters which can be exploited to inject malicious SQL code.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203