CVE-2018-5971: SQL Injection
Published Feb 17, 2018
·Updated
SQL Injection exists in the MediaLibrary Free 4.0.12 component for Joomla! via the id parameter or the mid array parameter.
Affected Software
1 affected component
Ordasoft Medialibrary Joomla\!=4.0.12
Event History
Feb 17, 2018
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Data Sourced
via NVD·07:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-5971?
CVE-2018-5971 is considered a high severity vulnerability due to the potential for SQL injection attacks.
2
How do I fix CVE-2018-5971?
To fix CVE-2018-5971, upgrade the MediaLibrary component to version 4.0.13 or later.
3
What platforms are affected by CVE-2018-5971?
CVE-2018-5971 affects Joomla! installations with the MediaLibrary Free version 4.0.12.
4
What types of attacks can be performed using CVE-2018-5971?
An attacker can exploit CVE-2018-5971 to execute arbitrary SQL queries on the database.
5
Is CVE-2018-5971 easy to exploit?
Yes, CVE-2018-5971 can be easily exploited with minimal technical skills using publicly available exploit techniques.