CVE-2020-37218: Joomla com_hdwplayer 4.2 SQL Injection via search.php
Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hdwplayersearch parameter. Attackers can submit POST requests with crafted SQL payloads in the hdwplayersearch parameter to extract sensitive database information from the hdwplayer_videos table.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37218?
CVE-2020-37218 is classified as a high severity SQL injection vulnerability.
How do I fix CVE-2020-37218?
To fix CVE-2020-37218, you should update Joomla com_hdwplayer to version 4.3 or later.
What type of vulnerability is CVE-2020-37218?
CVE-2020-37218 is an SQL injection vulnerability affecting the search.php file.
Who can exploit CVE-2020-37218?
CVE-2020-37218 can be exploited by unauthenticated attackers.
What parameters are involved in CVE-2020-37218?
The vulnerability in CVE-2020-37218 is triggered by injecting malicious code through the hdwplayersearch parameter.