Multiple SQL injection vulnerabilities in the Realtyna RPL (comrpl) component before 8.9.5 for Joomla! allow remote administrators to execute arbitrary SQL commands via the (1) id, (2) copyfield in a datacopy action, (3) pshow in an updatefield action, (4) css, (5) tip, (6) catid, (7) textsearch, (8) plisting, or (9) pwizard parameter to administrator/index.php.
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (comrpl) component before 8.9.5 for Joomla! allows remote attackers to hijack the authentication of administrators for requests that add a user via an adduser action to administrator/index.php.