Junglewise Threat Intelligence

CVE-2018-25380: eXtro.media eXtroForms SQL injection in filter parameters

CVE-2018-25380 · Severity: high · CVSS 7.1 · Published 2026-05-25

Executive brief

eXtroForms is a form-building extension for the Joomla content management system. A security flaw in this component allows a logged-in user to run unauthorized database commands. This could lead to the theft of sensitive customer data, exposure of administrative credentials, or unauthorized modification of website content.

Technical details

An SQL injection vulnerability exists in the eXtroForms component for Joomla, specifically within the 'extroformfield' view. The vulnerability is caused by improper neutralization of special elements in the 'filter_type_id', 'filter_pid_id', and 'filter_search' POST parameters. An authenticated attacker with low-level privileges can exploit this by submitting malicious SQL payloads to extract sensitive information from the database, including server data and user credentials. The exploit supports boolean-based blind, error-based, and time-based blind injection techniques. No official patch is explicitly detailed in the advisory, though the software is listed as version 2.1.5.

Affected products

  • eXtro.media eXtroForms 2.1.5 and earlier

Timeline

  • 2018-08-03: other: Vulnerability discovered by researcher
  • 2018-09-25: disclosed: Exploit published on Exploit-DB
  • 2026-05-25: advisory: CVE published/updated via VulnCheck

References