Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-625w-9wpc-g966

Опубликовано: 19 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 7.1

Описание

Joomla J-CruisePortal 6.0.4 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the guest_adult parameter. Attackers can send POST requests to the cruises endpoint with crafted SQL payloads in the guest_adult parameter to extract sensitive database information or manipulate database records.

Joomla J-CruisePortal 6.0.4 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the guest_adult parameter. Attackers can send POST requests to the cruises endpoint with crafted SQL payloads in the guest_adult parameter to extract sensitive database information or manipulate database records.

EPSS

Процентиль: 18%
0.00263
Низкий

7.1 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.1
nvd
2 месяца назад

Joomla J-CruisePortal 6.0.4 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the guest_adult parameter. Attackers can send POST requests to the cruises endpoint with crafted SQL payloads in the guest_adult parameter to extract sensitive database information or manipulate database records.

EPSS

Процентиль: 18%
0.00263
Низкий

7.1 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-89