Junglewise Threat Intelligence

CVE-2017-20273: Joomlashowroom Event Registration Pro Calendar SQL injection in id parameter

CVE-2017-20273 · Severity: high · CVSS 8.2 · Published 2026-06-19

Executive brief

A vulnerability exists in the Event Registration Pro Calendar plugin for Joomla, which is used to manage event bookings and schedules. An unauthorized attacker can exploit this flaw to access and extract sensitive information from the website's database. This could lead to the exposure of customer data, administrative credentials, or other confidential business information stored on the server.

Technical details

An SQL injection vulnerability (CWE-89) exists in the Joomla Event Registration Pro Calendar component version 4.1.3. The flaw is located in the 'id' parameter of the 'com_registrationpro' component when the 'view' is set to 'category'. An unauthenticated remote attacker can exploit this by sending a specially crafted GET request to index.php, allowing for the execution of arbitrary SQL commands. This can be used to bypass authentication or extract sensitive data from the underlying database via UNION-based injection techniques. Public exploit code is available on Exploit-DB.

Affected products

  • Joomlashowroom Event Registration Pro Calendar 4.1.3

Timeline

  • 2017-08-02: disclosed: Initial exploit published on Exploit-DB
  • 2026-06-19: advisory: NVD/VulnCheck advisory published

References