CVE-2018-25433

Vulnérabilités

CVE-2018-25433

Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injectin…

HIGH com_jephotogallery Composant

Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through the categoryid parameter. Attackers can send GET requests to index.php with crafted categoryid values in the com_jephotogallery component to execute arbitrary SQL queries and retrieve sensitive data like usernames and password hashes.

8.8 Élevée · CVSS 4.0

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Score retenu : NVD

SourceSévérité d'origineCVSS
NVDHIGH 8.8 (v4.0)
Produit
com_jephotogallery
Type
Composant
Corrigée dans
Non précisée
Publiée
01/06/2026
Modifiée
22/07/2026
CWE
CWE-89
  • JE Photo Gallery — 1.1 – 1.1

Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.

  1. Détectée via nvd26/09/2026 09:34 UTC