Executive brief
LMS King Professional is a learning management system plugin for the Joomla web platform. A security flaw allows unauthorized individuals to access and extract sensitive information from the website's database. This could lead to the exposure of student records, administrative credentials, or other private organizational data.
Technical details
An unauthenticated SQL injection vulnerability exists in the LMS King Professional component (com_lmsking) for Joomla, specifically within the learningpath layout. The flaw is located in the handling of the 'cp_id' parameter during GET requests to index.php. By crafting malicious SQL queries through this parameter, a remote attacker can bypass authentication to perform unauthorized database reads. The vulnerability is triggered when the 'task' parameter is set to 'learningPath' and the 'view' is set to 'lmsking'. This issue was publicly disclosed via an exploit-db entry and affects version 3.2.4.0.
Affected products
- King-products LMS King Professional 3.2.4.0
Timeline
- 2017-08-02: disclosed: Original exploit published on Exploit-DB
- 2026-06-19: advisory: CVE record published and NVD entry created