CVE-2023-23753
The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as concatenation is used to construct an SQL Query.
CRITICAL
visforms
Source officielle
Description
The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as concatenation is used to construct an SQL Query. An attacker can interact with the database and could be able to read, modify and delete data on it.
Sévérité
9.8
Critique · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | CRITICAL | 9.8 (v3.1) |
Produit et versions
- Produit
- visforms
- Corrigée dans
- 3.0.5
- Publiée
- 23/04/2023
- Modifiée
- 17/06/2026
- CWE
- CWE-89
Versions concernées
- Visforms Base Package for Joomla 3 — 3.0.4 – 3.0.4
- visforms — 3.0.0 – 3.0.5 (exclue)
Sources
- NVD CNA Joomla CVE-2023-23753 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:34 UTC