Executive brief
JooDatabase is a Joomla extension that allows administrators to display external database tables within Joomla sites. An unauthenticated SQL injection vulnerability in versions before 5.1.0 allows attackers to execute arbitrary SQL queries by manipulating the cid parameter, potentially leading to unauthorized data access, modification, or deletion of database contents.
Technical details
The vulnerability is a classic SQL injection flaw where the cid parameter is incorporated into database queries without proper input validation or parameterized statements. The vulnerability is unauthenticated, meaning no valid user credentials are required to exploit it. An attacker can craft malicious SQL statements in the cid parameter to extract sensitive data, modify records, or potentially execute administrative actions on the database. The fix is available in JooDatabase version 5.1.0 and later, where input validation and parameterized queries have been implemented.
Affected products
- Feenders JooDatabase before 5.1.0
Timeline
- 2026-09-03: disclosed