Junglewise Threat Intelligence

CVE-2017-20267: Joomlathat Calendar Planner SQL injection in category_id parameter

CVE-2017-20267 · Severity: high · CVSS 8.2 · Published 2026-06-19

Executive brief

Calendar Planner is a visual event management tool for Joomla websites. A security flaw in version 1.0.1 allows unauthorized individuals to run malicious database commands. This could lead to the theft of sensitive information, such as user data or site configuration details, directly from the website's database.

Technical details

An SQL injection vulnerability exists in the Calendar Planner component (version 1.0.1) for Joomla. The flaw is located in the 'events' view, where the 'category_id' parameter is not properly sanitized before being used in a database query. An unauthenticated remote attacker can exploit this by sending a specially crafted GET request containing malicious SQL code. Successful exploitation allows the attacker to extract sensitive information from the underlying database. While version 1.0.2 is mentioned in some documentation, users should ensure they are running a version later than 1.0.1 to mitigate this risk.

Affected products

  • Joomlathat Calendar Planner 1.0.1

Timeline

  • 2017-08-18: disclosed: Original exploit published on Exploit-DB
  • 2026-06-19: advisory: NVD/VulnCheck advisory published

References