CVE-2015-6513

j2store < 3.1.6 - SQL Injection via sortby or manufacturer_ids[] Parameter

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in the J2Store (com_j2store) extension before 3.1.7 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) sortby or (2) manufacturer_ids[] parameter to index.php.

References (3)

Core 3

Scores

EPSS 0.0217
EPSS Percentile 80.3%

Details

CWE
CWE-89
Status published
Products (1)
j2store/j2store < 3.1.6
Published Aug 18, 2015
Tracked Since Feb 18, 2026