Junglewise Threat Intelligence

CVE-2017-20262: Webkul Ajax Quiz SQL injection in cid parameter

CVE-2017-20262 · Severity: high · CVSS 8.2 · Published 2026-06-19

Vendors: Webkul.

Executive brief

Webkul Ajax Quiz is a Joomla extension used to create and manage interactive quizzes on websites. A security flaw in version 1.8 allows unauthorized individuals to access and extract sensitive information from the website's database. This could lead to the exposure of user data, site configurations, and other confidential information stored in the database.

Technical details

An SQL injection vulnerability exists in the Webkul Ajax Quiz component (com_ajaxquiz) version 1.8 for Joomla. The flaw is located in the 'cid' parameter handled by the 'ajaxquiz' view. An unauthenticated remote attacker can exploit this by sending specially crafted GET requests to index.php, using UNION-based SQL injection techniques to bypass intended query logic. Successful exploitation allows the attacker to extract sensitive metadata, such as table names and column structures, and potentially access sensitive record data from the underlying database. The extension has been unpublished from the Joomla Extensions Directory.

Affected products

  • Webkul Ajax Quiz 1.8

Timeline

  • 2017-08-21: disclosed: Initial exploit code published on Exploit-DB
  • 2026-06-19: advisory: CVE record published/updated by VulnCheck

References