Executive brief
JoomRecipe is a recipe management extension for the Joomla content management system. A security flaw in its search functionality allows an attacker to remotely access sensitive information from the website's database. This could lead to the exposure of user data, administrative credentials, or other confidential site information.
Technical details
A boolean-based blind SQL injection vulnerability exists in the JoomRecipe component (version 1.0.4) for Joomla. The flaw is located in the 'search_author' parameter handled by the search results endpoint. An unauthenticated remote attacker can exploit this by sending specially crafted POST requests to the search page. Successful exploitation allows the attacker to programmatically extract information from the underlying MySQL database by observing differences in application responses. While the advisory mentions version 1.0.4, newer versions like 6.9.0 are available which likely address this legacy issue.
Affected products
- Joomboost JoomRecipe 1.0.4
Timeline
- 2017-07-20: disclosed: Initial exploit published on Exploit-DB
- 2026-06-19: advisory: CVE record published/updated by VulnCheck