Junglewise Threat Intelligence

CVE-2017-20266: Joomshaper SP Movie Database SQL injection in searchword parameter

CVE-2017-20266 · Severity: high · CVSS 8.2 · Published 2026-06-19

Vendors: JoomShaper.

Executive brief

Joomshaper SP Movie Database is a Joomla extension used to manage and display movie directories. A security flaw in version 1.3 allows unauthorized individuals to run malicious database commands through the search feature. This could lead to the theft of sensitive information, such as user credentials or site configuration data, potentially compromising the entire website.

Technical details

An SQL injection vulnerability exists in the Joomshaper SP Movie Database extension version 1.3 for Joomla. The flaw is located in the 'searchresults' view, where the 'searchword' parameter is not properly sanitized before being used in a database query. An unauthenticated remote attacker can exploit this by sending a specially crafted GET request containing SQL payloads. Successful exploitation allows the attacker to extract sensitive information from the database or execute arbitrary SQL commands. The vulnerability was publicly documented with a proof-of-concept exploit in 2017, though the CVE was formally assigned later.

Affected products

  • Joomshaper SP Movie Database 1.3

Timeline

  • 2017-08-18: disclosed: Exploit-DB entry published by Ihsan Sencan
  • 2026-06-19: advisory: CVE record published by VulnCheck/NVD

References