Executive brief
eXtroForms is a form-building extension for the Joomla content management system. A security flaw in this component allows a logged-in user to run unauthorized database commands. This could lead to the theft of sensitive customer data, exposure of administrative credentials, or unauthorized modification of website content.
Technical details
An SQL injection vulnerability exists in the eXtroForms component for Joomla, specifically within the 'extroformfield' view. The vulnerability is caused by improper neutralization of special elements in the 'filter_type_id', 'filter_pid_id', and 'filter_search' POST parameters. An authenticated attacker with low-level privileges can exploit this by submitting malicious SQL payloads to extract sensitive information from the database, including server data and user credentials. The exploit supports boolean-based blind, error-based, and time-based blind injection techniques. No official patch is explicitly detailed in the advisory, though the software is listed as version 2.1.5.
Affected products
- eXtro.media eXtroForms 2.1.5 and earlier
Timeline
- 2018-08-03: other: Vulnerability discovered by researcher
- 2018-09-25: disclosed: Exploit published on Exploit-DB
- 2026-05-25: advisory: CVE published/updated via VulnCheck