Official Product Homepageproduct
http://joomboost.com/ CVE-2017-20277
HIGH
Joomla JoomRecipe 1.0.4 Component Blind SQL Injection via search_author
Record summary
CVE-2017-20277 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
Joomla JoomRecipe 1.0.4 component contains a blind SQL injection vulnerability in the search_author parameter on the search results page. Attackers can inject SQL code through POST requests to the search endpoint to extract database information using boolean-based blind SQL injection techniques.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 23, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Joomla JoomRecipeBrowse Joomboost / Joomla JoomRecipe | CVE List | 1.0.4 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBJoomla! Component JoomRecipe 1.0.4 - 'search_author' SQL InjectionExploitDB exploitby TengNot analyzed1 file
References
5Product Referenceproduct
https://extensions.joomla.org/extensions/extension/vertical-markets/food-a-beverage/joomrecipe nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-20277 ExploitDB-42347exploit
https://www.exploit-db.com/exploits/42347 VulnCheck Advisory: Joomla JoomRecipe 1.0.4 Component Blind SQL Injection via search_authorThird-party advisory
https://www.vulncheck.com/advisories/joomla-joomrecipe-component-blind-sql-injection-via-search-author