Joomla 扩展 iCagenda.com 中的 iCagenda < 4.0.0-4.0.11 存在未认证的 SQL 注入漏洞。该漏洞存在于 mod_icagenda_calendar 模块中,可通过 com_ajax 访问,无需会话、令牌或账户即可触发。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| icagenda.com | iCagenda extension for Joomla | 4.0.0-4.0.11 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| icagenda.com | iCagenda extension for Joomla | 4.0.0-4.0.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71571 | 8.6 HIGH | Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter |
| CVE-2026-67366 | 5.3 MEDIUM | Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0. |
| CVE-2026-71570 | 5.1 MEDIUM | Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4 |
No comments yet