Record summary

CVE-2018-17254 has a selected CVSS score of 9.8 (critical); EIP currently links 2 catalogued exploits, 3 repository PoCs, and 1 Nuclei template.

Description

The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 14, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
2
Repository PoCs
3
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

5

Catalogued exploits

ExploitDBJoomla! Component JCK Editor 6.4.4 - 'parent' SQL InjectionExploitDB exploitby Hamza MegahedNot analyzed1 file
ExploitDB

PoC details
ExploitDBJoomla JCK Editor 6.4.4 - 'parent' SQL Injection (2)ExploitDB exploitby Nicholas FerreiraNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubFachrulRH/jckeditorRepository PoCby FachrulRHStars: 5Not analyzed2 files

2.3 KiB

GitHub

PoC details
GitHubNickguitar/Joomla-JCK-Editor-6.4.4-SQL-InjectionRepository PoCby NickguitarStars: 10Not analyzed2 files

13.5 KiB

GitHub

PoC details
GitHubMataKucing-OFC/CVE-2018-17254Repository PoCby MataKucing-OFCStars: 0Not analyzed2 files

12.9 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALJoomla! JCK Editor SQL InjectionCVSS 9.8

The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation, or data leakage.

Remediation

Update or remove the affected plugin.

WeaknessesCWE-89
AuthorsSuman_Kar
Template tagscvecve2018packetstormedbjoomlasqliarkextensionsjoomla\!vkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:arkextensions:jck_editor:6.4.4:*:*:*:*:joomla\!:*:*

Source: ProjectDiscovery

References

3