Vulnerability Bulletins

[20180104] - Core - SQLi vulnerability in Hathor postinstall message

   
Affected software Joomla
 
Project: Joomla! SubProject: CMS Impact: High Severity: Low Versions: 3.7.0 through 3.8.3 Exploit type: SQLi Reported Date: 2017-November-17 Fixed Date: 2018-January-30 CVE Number: CVE-2018-6376 Description The lack of type casting of a variable in SQL statement leads to a SQL injection vulnerability in the Hathor postinstall message. Affected Installs Joomla! CMS versions 3.7.0 through 3.8.3 Solution Upgrade to version 3.8.4 Contact The JSST at the Joomla! Security Centre. Reported By: Karim

More info:

http://feeds.joomla.org/~r/JoomlaSecurityNews/~3/4FowU4F_AXA/722-20180104-core-sqli-vulnerability.html