Executive brief
KissGallery is a photo gallery extension for the Joomla! content management system. A security flaw in this component allows unauthorized individuals to run malicious database commands by simply visiting a specific web link. This could lead to the theft of sensitive website data, including user information or administrative credentials, potentially compromising the entire website.
Technical details
An SQL injection vulnerability (CWE-89) exists in the KissGallery component (version 1.0.0) for Joomla!. The flaw is located within the handling of the component's URL path, where input is not properly neutralized before being used in an SQL query. An unauthenticated remote attacker can exploit this by sending a specially crafted HTTP request to the kissgallery endpoint. Successful exploitation allows the attacker to execute arbitrary SQL commands against the backend database, potentially leading to full data exfiltration. The extension has been unpublished from the Joomla! Extensions Directory due to this vulnerability.
Affected products
- Terrywcarter KissGallery 1.0.0
Timeline
- 2026-06-19: advisory: NVD and VulnCheck published advisory details.
- 2026-06-19: disclosed