CVE-2010-10003 MEDIUM

CVE-2010-10003: gesellix titlelink plugin_content_title.php sql injection

Vendor Gesellix
Product titlelink
Weakness CWE-89 · SQLi
Published January 4, 2023
Last update November 25, 2024

CVSS base score

5.5/10
Attack vector Adjacent
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

A vulnerability classified as critical was found in gesellix titlelink on Joomla. Affected by this vulnerability is an unknown functionality of the file plugin_content_title.php. The manipulation of the argument phrase leads to sql injection. The patch is named b4604e523853965fa981a4e79aef4b554a535db0. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217351.

Explanation of Vulnerability in Simple Terms

02Summary

Titlelink contains a SQL injection vulnerability in all versions. An attacker with low-level privileges and adjacent network access can inject malicious SQL commands to read, modify, or delete database records. The vulnerability requires no user interaction and affects confidentiality, integrity, and availability of stored data.

What an attacker can do

03Attacker Capabilities

Inject SQL commands to read, modify, or delete database records.

Potential impact on your site

04Site Impact

Database contents may be exposed, altered, or deleted by an authenticated attacker on the local network.

Conditions required to exploit

05Prerequisites

Low-level user account and adjacent network access to the affected system.

Key dates

06Disclosure timeline

January 4, 2023 CVE published
November 25, 2024 Record updated