Executive brief
Flip Wall is a Joomla component used to create interactive displays for portfolios, sponsors, and team members. A security flaw in version 8.0 allows an unauthenticated attacker to run unauthorized database commands. This could lead to the theft of sensitive information, such as user credentials or private site data, potentially compromising the entire website.
Technical details
A SQL injection vulnerability exists in the Flip Wall component (com_flipwall) for Joomla! version 8.0. The flaw is located in the 'click' task within index.php, where the 'wallid' parameter is not properly sanitized before being used in a database query. An unauthenticated remote attacker can exploit this by sending a specially crafted GET request containing SQL payloads. Successful exploitation allows the attacker to extract sensitive information from the database, including administrative credentials or configuration data. While the vendor has released newer versions (e.g., v15.0), users on version 8.0 should upgrade immediately to mitigate this risk.
Affected products
- Pulseextensions Flip Wall 8.0
Timeline
- 2017-08-21: disclosed: Initial exploit published on Exploit-DB
- 2026-06-19: advisory: NVD/VulnCheck advisory published