Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wgm5-xp28-5cmg

Опубликовано: 16 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3

Описание

Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specification) GET array parameters on Phoca Cart's public shop items page are concatenated raw into SQL WHERE clauses without parameterization or escaping. An unauthenticated attacker can inject arbitrary SQL through these parameters, enabling full database extraction via time-based blind techniques.

Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specification) GET array parameters on Phoca Cart's public shop items page are concatenated raw into SQL WHERE clauses without parameterization or escaping. An unauthenticated attacker can inject arbitrary SQL through these parameters, enabling full database extraction via time-based blind techniques.

EPSS

Процентиль: 30%
0.00372
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-89

Связанные уязвимости

nvd
3 дня назад

Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specification) GET array parameters on Phoca Cart's public shop items page are concatenated raw into SQL WHERE clauses without parameterization or escaping. An unauthenticated attacker can inject arbitrary SQL through these parameters, enabling full database extraction via time-based blind techniques.

EPSS

Процентиль: 30%
0.00372
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-89