ZeroHour

CVE-2018-14592

PoC
CVSS 3.0
9.8 critical
EPSS
3%p87
Published
()
Modified
Description

The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection within download.php.

Vendors
cwjoomla
Products
cw article attachments free, cw article attachments pro
Ecosystems
Joomla
Weakness
CWE-89
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.