CVE-2019-19846: SQL Injection
Published Dec 18, 2019
·Updated
In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors.
Affected Software
1 affected component
Joomla Joomla\!>=2.5.0<=3.9.14
Event History
Dec 18, 2019
CVE Published
via MITRE·03:49 AM
Data Sourced
via MITRE·03:49 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-19846?
CVE-2019-19846 has a high severity rating due to its potential for SQL injection exploits.
2
How do I fix CVE-2019-19846?
To fix CVE-2019-19846, update Joomla! to version 3.9.14 or later to address the SQL injection vulnerabilities.
3
Which versions of Joomla! are affected by CVE-2019-19846?
CVE-2019-19846 affects Joomla! versions prior to 3.9.14, including all versions from 2.5.0 to 3.9.13.
4
What types of vulnerabilities does CVE-2019-19846 include?
CVE-2019-19846 includes various SQL injection vulnerabilities due to lack of validation of configuration parameters.
5
Who is impacted by CVE-2019-19846?
Anyone using an affected version of Joomla! prior to 3.9.14 is at risk from CVE-2019-19846.