CVE-2018-8045: SQL Injection
Published Mar 14, 2018
·Updated
In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view.
Affected Software
1 affected component
Joomla Joomla\!>=3.5.0<=3.8.5
Event History
Mar 14, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Mar 15, 2018
Data Sourced
via NVD·01:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-8045?
CVE-2018-8045 is classified as a high severity vulnerability due to its potential for SQL injection.
2
How do I fix CVE-2018-8045?
To fix CVE-2018-8045, update your Joomla! installation to version 3.8.6 or later.
3
Which versions of Joomla! are affected by CVE-2018-8045?
CVE-2018-8045 affects Joomla! versions from 3.5.0 to 3.8.5.
4
What type of vulnerability is CVE-2018-8045?
CVE-2018-8045 is a SQL injection vulnerability stemming from improper type casting of a variable.
5
Who can be impacted by CVE-2018-8045?
Websites using affected versions of Joomla! are at risk of exploitation through unauthorized database access.