Junglewise Threat Intelligence

CVE-2017-20256: JoomPlace Survey Force Deluxe SQL injection in invite parameter

CVE-2017-20256 · Severity: high · CVSS 8.2 · Published 2026-06-19

Executive brief

JoomPlace Survey Force Deluxe is a Joomla extension used for creating and managing online surveys and polls. A security flaw in version 3.2.4 allows unauthorized individuals to run malicious database commands by sending a specially crafted web link. This could lead to the theft of sensitive information stored in the website's database, such as user data or survey results.

Technical details

An SQL injection vulnerability exists in JoomPlace Survey Force Deluxe 3.2.4 within the 'invite' parameter of the 'com_surveyforce' component. The flaw is triggered when the application fails to properly sanitize input passed via GET requests to the 'start_invited' task. An unauthenticated remote attacker can exploit this by sending crafted SQL payloads to extract sensitive data from the underlying database. The vulnerability has been documented in public exploit code (EDB-42606), and the extension has since been unpublished from the Joomla Extensions Directory.

Affected products

  • JoomPlace Survey Force Deluxe 3.2.4

Timeline

  • 2017-09-03: disclosed: Original exploit published on Exploit-DB
  • 2026-06-19: advisory: NVD/VulnCheck advisory published

References