CVE-2020-19451
SQL injection exists in the jdownloads 3.2.63 component for Joomla!
HIGH
jdownloads
Composant
Description
SQL injection exists in the jdownloads 3.2.63 component for Joomla! via com_jdownloads/helpers/jdownloadshelper.php, updateLog function via the X-forwarded-for Header parameter.
Sévérité
7.5
Élevée · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | HIGH | 7.5 (v3.1) |
Produit et versions
- Produit
- jdownloads
- Type
- Composant
- Corrigée dans
- Non précisée
- Publiée
- 25/09/2020
- Modifiée
- 17/06/2026
- CWE
- CWE-89
Versions concernées
- jdownloads — 3.2.63 – 3.2.63
Sources
- NVD CVE-2020-19451 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:34 UTC