CVE-2018-6376: SQL Injection
Published Jan 30, 2018
·Updated
In Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Hathor postinstall message.
Affected Software
1 affected component
Joomla Joomla\!<3.8.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Joomla!to a version that resolves this vulnerability.Fixed in 3.8.4
Event History
Jan 30, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6376?
CVE-2018-6376 is classified as a critical SQL injection vulnerability.
2
How do I fix CVE-2018-6376?
To fix CVE-2018-6376, upgrade Joomla! to version 3.8.4 or later.
3
What type of vulnerability is CVE-2018-6376?
CVE-2018-6376 is a SQL injection vulnerability caused by improper type casting in SQL statements.
4
What versions of Joomla! are affected by CVE-2018-6376?
CVE-2018-6376 affects Joomla! versions prior to 3.8.4.
5
Can CVE-2018-6376 lead to data compromise?
Yes, CVE-2018-6376 can potentially lead to unauthorized access and data compromise.