Product Referenceproduct
https://extensions.joomla.org/extensions/extension/directory-a-documentation/downloads/osdownloads CVE-2017-20259
HIGH
Joomla OSDownloads 1.7.4 SQL Injection via item view
Record summary
CVE-2017-20259 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
Joomla OSDownloads 1.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_osdownloads&view=item&id=[SQL] to extract sensitive database information including credentials and configuration data.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 23, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
OSDownloadsBrowse Joomlashack / OSDownloads | CVE List | 1.7.4 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBJoomla! Component OSDownloads 1.7.4 - SQL InjectionExploitDB exploitby Ihsan SencanNot analyzed1 file
References
5Official Product Homepageproduct
https://joomlashack.com/ nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-20259 ExploitDB-42561exploit
https://www.exploit-db.com/exploits/42561 VulnCheck Advisory: Joomla OSDownloads 1.7.4 SQL Injection via item viewThird-party advisory
https://www.vulncheck.com/advisories/joomla-osdownloads-sql-injection-via-item-view