First published: Mon Mar 16 2020(Updated: )
An issue was discovered in Joomla! before 3.9.16. The lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Featured Articles frontend menutype.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | >=1.7.0<3.9.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10243 is considered a critical vulnerability due to the potential for SQL injection attacks.
To fix CVE-2020-10243, update Joomla! to version 3.9.16 or later.
CVE-2020-10243 affects all Joomla! versions prior to 3.9.16.
Exploiting CVE-2020-10243 allows attackers to execute arbitrary SQL commands, potentially leading to data leakage or corruption.
No, attackers do not need authenticated access to exploit CVE-2020-10243, making it more dangerous.