LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2020-37224

Published
CVSS7.1
Severityhigh
WeaknessCWE-89
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Description

Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Attackers can send POST requests to the administrator index with malicious 'sortby' values to extract sensitive database information.

References

← Back to the CVE Tracker

Our coverage of CVE-2020-37224

No stories yet. This page updates automatically when we publish reporting that references CVE-2020-37224.