CVE-2019-19846

CRITICAL

Joomla! < 3.9.14 - SQL Injection via Configuration Parameters

Title source: llm
STIX 2.1

Description

In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors.

Scores

CVSS v3 9.8
EPSS 0.0137
EPSS Percentile 80.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
joomla/joomla\! 2.5.0 - 3.9.14
Published Dec 18, 2019
Tracked Since Feb 18, 2026