What the vulnerability does
01Description
A vulnerability classified as critical was found in gesellix titlelink on Joomla. Affected by this vulnerability is an unknown functionality of the file plugin_content_title.php. The manipulation of the argument phrase leads to sql injection. The patch is named b4604e523853965fa981a4e79aef4b554a535db0. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217351.
Explanation of Vulnerability in Simple Terms
02Summary
Titlelink contains a SQL injection vulnerability in all versions. An attacker with low-level privileges and adjacent network access can inject malicious SQL commands to read, modify, or delete database records. The vulnerability requires no user interaction and affects confidentiality, integrity, and availability of stored data.
What an attacker can do
03Attacker Capabilities
Inject SQL commands to read, modify, or delete database records.
Potential impact on your site
04Site Impact
Database contents may be exposed, altered, or deleted by an authenticated attacker on the local network.
Conditions required to exploit
05Prerequisites
Low-level user account and adjacent network access to the affected system.
Key dates
06Disclosure timeline
January 4, 2023
CVE published
November 25, 2024
Record updated