Junglewise Threat Intelligence

CVE-2017-20272: Faboba Ultimate Property Listing SQL injection in sf_selectuser_id

CVE-2017-20272 · Severity: high · CVSS 8.2 · Published 2026-06-19

Executive brief

A security vulnerability exists in the Ultimate Property Listing extension for Joomla, which is used to manage real estate listings on websites. An unauthorized attacker can exploit this flaw to access the website's underlying database without needing a password. This could lead to the theft of sensitive information, including user data and site configuration details.

Technical details

An SQL injection vulnerability exists in Joomla Ultimate Property Listing version 1.0.2 due to improper neutralization of special elements in the 'sf_selectuser_id' parameter. An unauthenticated remote attacker can exploit this by sending specially crafted GET requests to index.php with 'option=com_upl' and 'view=propertylisting' parameters. Successful exploitation allows the attacker to execute arbitrary SQL commands, enabling the extraction of sensitive database information such as table names, column structures, and stored data. The vulnerability is classified as CWE-89.

Affected products

  • Faboba Ultimate Property Listing 1.0.2

Timeline

  • 2026-06-19: disclosed: CVE published/updated via VulnCheck and NVD

References