Joomla 扩展 - joomcode.com - JCTables 1.21.1 中未认证的 SQL 注入漏洞,存在于读取和写入查询中 前端 CRUD API 控制器未对任何任务执行 Joomla 令牌验证或身份认证检查。表名、列名及值直接取自请求参数,并被拼接到 SQL 查询语句中,从而导致在读取和写入操作中均可被利用进行 SQL 注入攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| joomcode.com | JCTables extension for Joomla | 1.0.0-1.20.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet