Executive brief
StreetGuessr Game is a gaming extension for the Joomla content management system. A security flaw in version 1.1.8 allows unauthorized individuals to access the website's underlying database. This could lead to the theft of sensitive information, including user data and site configuration details, potentially compromising the entire website.
Technical details
An SQL injection vulnerability exists in the StreetGuessr Game extension (com_streetguess) for Joomla, specifically within version 1.1.8. The flaw is located in the handling of the 'catid' parameter when the 'view' is set to 'maps'. An unauthenticated remote attacker can exploit this by sending a specially crafted GET request to index.php, allowing for the execution of arbitrary SQL commands. This can be used to extract sensitive information from the database, such as database names and version information. The vulnerability is classified as CWE-89.
Affected products
- Nordmograph StreetGuessr Game 1.1.8
Timeline
- 2026-06-19: disclosed: NVD publication date