Joomla 扩展 - cmsjunkie.com - J-BusinessDirectory < 6.2.3 版本中“旅行”搜索功能存在 SQL 注入漏洞。攻击者可通过构造恶意输入,将搜索关键词和 ORDER BY 子句拼接到 SQL 查询中,从而实施注入攻击。在 6.2.3 版本中,开发人员对关键词进行了引号转义处理,并对排序字段实施了白名单机制,从而修复了该漏洞。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| cmsjunkie.com | J-BusinessDirectory extension for Joomla | 1.0.0-6.2.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cmsjunkie.com | J-BusinessDirectory extension for Joomla | 1.0.0-6.2.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75949 | 10.0 CRITICAL | Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J |
| CVE-2026-75956 | 8.7 HIGH | Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-Busine |
| CVE-2026-75951 | 6.9 MEDIUM | Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/AP |
| CVE-2026-75950 | 6.9 MEDIUM | Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-Busines |
| CVE-2026-75955 | 5.1 MEDIUM | Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < |
| CVE-2026-75952 | 4.6 MEDIUM | Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6. |
| CVE-2026-75953 | Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 |
No comments yet