Executive brief
JE Photo Gallery, a plugin for the Joomla content management system used to display image galleries, contains a security flaw. An unauthenticated attacker can exploit this to access the website's underlying database. This could lead to the theft of sensitive information, including administrative usernames and encrypted password hashes, potentially resulting in a full site takeover.
Technical details
A SQL injection vulnerability exists in the JE Photo Gallery component (com_jephotogallery) for Joomla version 1.1. The flaw is located in the 'categoryid' parameter handled by the 'fetchimage' task within the category view. An unauthenticated remote attacker can send specially crafted GET requests to index.php to execute arbitrary SQL commands. This allows for the extraction of sensitive data from the Joomla database, such as the 'users' table containing usernames and password hashes. The vulnerability stems from improper neutralization of special elements used in SQL commands (CWE-89).
Affected products
- JoomlaExtensions JE Photo Gallery 1.1
Timeline
- 2018-11-26: disclosed: Initial discovery by researcher Ihsan Sencan
- 2018-12-03: other: Exploit published on Exploit-DB
- 2026-06-01: advisory: CVE published/updated in NVD dataset