Junglewise Threat Intelligence

CVE-2017-20270: Raindrops Infotech Twitch Tv SQL injection in com_twitchtv

CVE-2017-20270 · Severity: high · CVSS 8.2 · Published 2026-06-19

Executive brief

The Twitch Tv component for Joomla, which allows websites to integrate Twitch streaming content, contains a security flaw. An unauthorized attacker can use this flaw to access the website's database, potentially stealing sensitive information such as user credentials and site configuration data. This could lead to a full compromise of the website and its data.

Technical details

An SQL injection vulnerability exists in the Raindrops Infotech Twitch Tv component version 1.1 for Joomla. The flaw is located within the handling of the 'username' and 'id' parameters when the 'option' is set to 'com_twitchtv' in GET requests to index.php. Because these parameters are not properly sanitized before being used in database queries, an unauthenticated remote attacker can inject malicious SQL payloads. This allows for the extraction of sensitive information from the database, including administrative credentials and system configuration. The vulnerability was publicly disclosed with proof-of-concept exploits available on Exploit-DB.

Affected products

  • Raindrops Infotech Twitch Tv 1.1

Timeline

  • 2017-08-18: disclosed: Initial exploit published on Exploit-DB
  • 2026-06-19: advisory: CVE published and NVD record created

References