CVE-2019-19846

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
18/12/2019
Last modified:
18/12/2019

Description

In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:* 2.5.0 (including) 3.9.14 (including)