Executive brief
Joomlashack OSDownloads is a Joomla extension used to manage file downloads and collect email addresses from site visitors. A security flaw in version 1.7.4 allows remote attackers to access the website's underlying database without needing a password. This could lead to the theft of sensitive information, including user credentials and site configuration data.
Technical details
An SQL injection vulnerability exists in the OSDownloads extension (version 1.7.4) for Joomla. The flaw is located in the 'id' parameter of the 'item' view within the 'com_osdownloads' component. An unauthenticated attacker can exploit this by sending a specially crafted GET request to index.php, allowing for the execution of arbitrary SQL commands. This can be used to bypass authentication or exfiltrate sensitive data from the database, such as administrative credentials and configuration details. The vulnerability was publicly documented with a proof-of-concept exploit in 2017.
Affected products
- Joomlashack OSDownloads 1.7.4
Timeline
- 2017-08-25: disclosed: Public exploit published on Exploit-DB
- 2026-06-19: advisory: NVD/VulnCheck advisory published