Junglewise Threat Intelligence

CVE-2017-20253: Gegabyte My Projects SQL injection in VerAyari parameter

CVE-2017-20253 · Severity: high · CVSS 8.2 · Published 2026-06-19

Executive brief

The My Projects component for Joomla, which is used to display portfolios and professional work on websites, contains a security flaw. An unauthenticated attacker can use this flaw to access the website's database, potentially stealing sensitive information such as user credentials and system data. This could lead to a full compromise of the website and its associated data.

Technical details

A SQL injection vulnerability exists in the 'My Projects' component (version 2.0) for Joomla! within the 'VerAyari' parameter. The root cause is improper neutralization of special elements used in SQL commands (CWE-89). An unauthenticated remote attacker can exploit this by sending specially crafted HTTP requests to the component endpoint. Successful exploitation allows for the execution of arbitrary SQL queries, enabling the attacker to extract sensitive information from the database, including administrative credentials and system configuration. While version 2.1 is available, users should verify if the patch addresses this specific vulnerability.

Affected products

  • Gegabyte My Projects 2.0

Timeline

  • 2017-12-18: disclosed: Original exploit published on Exploit-DB
  • 2026-06-19: advisory: NVD/VulnCheck advisory published

References