Official Product Homepageproduct
http://joomplace.com/ CVE-2017-20256
HIGH
Joomla Survey Force Deluxe 3.2.4 SQL Injection via invite Parameter
Record summary
CVE-2017-20256 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the invite parameter. Attackers can send GET requests to the component with crafted SQL payloads in the invite parameter to extract sensitive database information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 23, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Survey Force DeluxeBrowse Joomplace / Survey Force Deluxe | CVE List | 3.2.4 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBJoomla! Component Survey Force Deluxe 3.2.4 - 'invite' SQL InjectionExploitDB exploitby Ihsan SencanNot analyzed1 file
References
5Product Referenceproduct
https://extensions.joomla.org/extensions/extension/contacts-and-feedback/surveys/survey-force-deluxe nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-20256 ExploitDB-42606exploit
https://www.exploit-db.com/exploits/42606 VulnCheck Advisory: Joomla Survey Force Deluxe 3.2.4 SQL Injection via invite ParameterThird-party advisory
https://www.vulncheck.com/advisories/joomla-survey-force-deluxe-sql-injection-via-invite-parameter