CVE-2018-17254
CRITICALNuclei
arkextensions jck_editor Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Record summary
CVE-2018-17254 has a selected CVSS score of 9.8 (critical); EIP currently links 2 catalogued exploits, 3 repository PoCs, and 1 Nuclei template.
Description
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
jck_editorBrowse arkextensions / jck_editor | VulnCheck | Version data not supplied | |
Proofs of concept
5Catalogued exploits
ExploitDBJoomla! Component JCK Editor 6.4.4 - 'parent' SQL InjectionExploitDB exploitby Hamza MegahedNot analyzed1 file
ExploitDBJoomla JCK Editor 6.4.4 - 'parent' SQL Injection (2)ExploitDB exploitby Nicholas FerreiraNot analyzed1 file
Repository PoCs
GitHubFachrulRH/jckeditorRepository PoCby FachrulRHStars: 5Not analyzed2 files
GitHubNickguitar/Joomla-JCK-Editor-6.4.4-SQL-InjectionRepository PoCby NickguitarStars: 10Not analyzed2 files
GitHubMataKucing-OFC/CVE-2018-17254Repository PoCby MataKucing-OFCStars: 0Not analyzed2 files
Nuclei templates
1ProjectDiscoveryCRITICALJoomla! JCK Editor SQL InjectionCVSS 9.8
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation, or data leakage.
Remediation
Update or remove the affected plugin.
WeaknessesCWE-89
AuthorsSuman_Kar
Template tagscvecve2018packetstormedbjoomlasqliarkextensionsjoomla\!vkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:arkextensions:jck_editor:6.4.4:*:*:*:*:joomla\!:*:*
http://packetstormsecurity.com/files/161683/Joomla-JCK-Editor-6.4.4-SQL-Injection.html https://www.exploit-db.com/exploits/45423/ https://github.com/Nickguitar/Joomla-JCK-Editor-6.4.4-SQL-Injection https://github.com/ARPSyndicate/cvemon https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3packetstormsecurity.com
http://packetstormsecurity.com/files/161683/Joomla-JCK-Editor-6.4.4-SQL-Injection.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-17254 45423exploit
https://www.exploit-db.com/exploits/45423