Junglewise Threat Intelligence

CVE-2017-20268: Zcontent Zap Calendar Lite SQL injection in RSVP plugin

CVE-2017-20268 · Severity: high · CVSS 8.2 · Published 2026-06-19

Executive brief

Zap Calendar Lite is a popular event management and calendar plugin for the Joomla content management system. A security flaw in version 4.3.4 allows unauthenticated attackers to access and extract sensitive information from the website's database. This could lead to the exposure of user data, site configurations, and internal database structures, potentially compromising the entire website.

Technical details

An SQL injection vulnerability exists in the Zap Calendar Lite component (version 4.3.4) for Joomla. The flaw is located within the 'eid' parameter of the RSVP plugin endpoint. An unauthenticated remote attacker can exploit this by sending specially crafted GET requests containing malicious SQL payloads. Successful exploitation allows the attacker to execute arbitrary SQL queries, enabling the extraction of sensitive database information such as database names, table structures, and potentially administrative credentials or user data. The vulnerability was publicly disclosed via Exploit-DB (ID 42500).

Affected products

  • Zcontent Zap Calendar Lite 4.3.4

Timeline

  • 2017-08-15: disclosed: Original exploit published on Exploit-DB
  • 2026-06-19: advisory: NVD/VulnCheck advisory published

References