CVE-2026-74251
Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6
Description
Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specification) GET array parameters on Phoca Cart's public shop items page are concatenated raw into SQL WHERE clauses without parameterization or escaping. An unauthenticated attacker can inject arbitrary SQL through these parameters, enabling full database extraction via time-based blind techniques.
Sévérité
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | CRITICAL | 9.3 (v4.0) |
Produit et versions
- Produit
- Extension Joomla — phoca.cz
- Corrigée dans
- Non précisée
- Publiée
- 16/08/2026
- Modifiée
- 26/08/2026
- CWE
- CWE-89
Versions concernées
- Phoca Cart extension for Joomla — 5.0.0 – 6.1.6
Sources
- NVD CNA Joomla CVE-2026-74251 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:34 UTC