Junglewise Threat Intelligence

CVE-2017-20263: Focalpointx FocalPoint Pro/Free SQL injection in location view

CVE-2017-20263 · Severity: high · CVSS 8.2 · Published 2026-06-19

Executive brief

FocalPoint is a Joomla component used for managing and displaying locations on maps. A security flaw allows unauthorized individuals to access the website's database without a password. This could lead to the theft of sensitive customer information or website data, potentially disrupting business operations and damaging the organization's reputation.

Technical details

An unauthenticated SQL injection vulnerability exists in the FocalPoint Pro/Free component (version 1.2.3) for Joomla. The flaw is located in the handling of the 'id' parameter when the 'view' is set to 'location'. By sending a specially crafted GET request to index.php, an attacker can bypass input sanitization to execute arbitrary SQL commands. This allows for the extraction of sensitive data from the underlying database. The vulnerability is exploitable over the network without any user interaction or prior authentication.

Affected products

  • Focalpointx FocalPoint Pro / Free 1.2.3

Timeline

  • 2017-08-21: disclosed: Initial exploit published on Exploit-DB
  • 2026-06-19: advisory: CVE published/updated in NVD

References