What the vulnerability does
01Description
Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Polling Reloaded < 5.6.1
CVSS base score
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
What the vulnerability does
Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Polling Reloaded < 5.6.1
Explanation of Vulnerability in Simple Terms
The Sexy Polling Reloaded extension for Joomla contains a SQL injection vulnerability in versions 1.0.0 through 5.6.0. An attacker can inject malicious SQL commands through unfiltered input to read, modify, or delete database contents. No authentication or user interaction is required to exploit this vulnerability. Site administrators should update to a patched version immediately.
What an attacker can do
Read, modify, or delete data from the site's database without authentication.
Potential impact on your site
Attackers can steal user data, modify site content, or disable the site entirely via database manipulation.
Conditions required to exploit
Network access to the Joomla site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities