Vulnerability Bulletins

[20180301] - Core - SQLi vulnerability User Notes

   
Affected software Joomla
 
Project: Joomla! SubProject: CMS Impact: High Severity: Low Versions: 3.5.0 through 3.8.5 Exploit type: SQLi Reported Date: 2018-March-08 Fixed Date: 2018-March-12 CVE Number: CVE-2018-8045 Description The lack of type casting of a variable in SQL statement leads to a SQL injection vulnerability in the User Notes list view Affected Installs Joomla! CMS versions 3.5.0 through 3.8.5 Solution Upgrade to version 3.8.6 Contact The JSST at the Joomla! Security Centre. Reported By: Entropy Moe

More info:

http://feeds.joomla.org/~r/JoomlaSecurityNews/~3/lncFKmG4klo/723-20180301-core-sqli-vulnerability.html