CVE-2018-8045

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
15/03/2018
Last modified:
09/04/2018

Description

In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:* 3.5.0 (including) 3.8.5 (including)