Executive brief
Bargain Product VM3 is a Joomla extension used for managing product deals. A security flaw allows unauthorized individuals to access and extract sensitive information from the website's database. This could lead to the exposure of customer data, administrative credentials, or other confidential business information.
Technical details
An SQL injection vulnerability exists in the Bargain Product VM3 component (version 1.0) for Joomla. The flaw is located within the 'product_id' parameter handled by the 'brainy' and 'alice' views. An unauthenticated remote attacker can exploit this by sending specially crafted GET requests containing malicious SQL statements. Successful exploitation allows the attacker to bypass authentication, view sensitive database records, and potentially modify data depending on database permissions. The vulnerability was publicly documented with proof-of-concept exploits in 2017.
Affected products
- Weborange Bargain Product VM3 1.0
Timeline
- 2017-08-24: disclosed: Public exploit published on Exploit-DB
- 2026-06-19: advisory: CVE record published and enriched by NVD/VulnCheck