Joomla com_hdwplayer 4.2 SQL Injection via search.php
Vulnerability Description
Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hdwplayersearch parameter. Attackers can submit POST requests with crafted SQL payloads in the hdwplayersearch parameter to extract sensitive database information from the hdwplayer_videos table.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-37218
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- qw3rTyTy
Affected Vendor
Hdwplayer
View all reports →