Description
A vulnerability in the J2Store component for Joomla! allows attackers to inject and execute SQL commands on the website’s database, potentially leading to data theft, manipulation, or unauthorized access.
Recommendation
To mitigate the risk, upgrade J2Store to the latest stable version, which includes patches for the vulnerability (version 3.3.7 and above).
References
Related Issues
- Joomla! Component JEXTN Video Gallery 3.0.5 'id' SQLI - CVE-2017-17872
- Joomla! Component JCK Editor 6.4.4 'parent' SQLI - CVE-2018-17254
- Joomla! Component JB Bus 2.3 'order_number' SQLI - CVE-2018-6372
- Joomla! Component InviteX 3.0.5 'invite_type' SQLI - CVE-2018-6394
You might also like:
- Tags:
- Joomla
- SQL Injection
Anything's wrong? Let us know Last updated on May 13, 2024


