CVE-2018-14592
Published Sep 20, 2018The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection within download.php.
Vendor archive
2 CVEs tagged to vendor cwjoomla — 2 Critical, 0 High, 0 Medium, 0 Low, 0 Unrated.
The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection within download.php.
SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter.