Junglewise Threat Intelligence

CVE-2017-20276: Simbunch SIMGenealogy SQL injection in type parameter

CVE-2017-20276 · Severity: high · CVSS 8.2 · Published 2026-06-19

Executive brief

SIMGenealogy is a genealogy and family tree extension for the Joomla! content management system. A security flaw allows unauthenticated attackers to access and extract sensitive information from the website's database. This could lead to the exposure of private user data or administrative information, potentially compromising the entire website.

Technical details

An SQL injection vulnerability exists in the SIMGenealogy component (version 2.1.5) for Joomla!. The flaw is located in the 'type' parameter handled by the 'latest' view of the 'com_simgenealogy' component. An unauthenticated remote attacker can exploit this by sending a specially crafted GET request to index.php. Successful exploitation allows the attacker to execute arbitrary SQL commands, enabling the extraction of sensitive data from the underlying database. The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command).

Affected products

  • Simbunch (Joomla!) SIMGenealogy 2.1.5

Timeline

  • 2017-08-02: disclosed: Original exploit published on Exploit-DB
  • 2026-06-19: advisory: NVD/VulnCheck advisory published

References