Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the ajaxaction.flag_question task. Attackers can inject malicious SQL code via the stu_quiz_id or flag_quest parameters to manipulate database queries and extract sensitive information.
References
| Link | Resource |
|---|---|
| http://joomplace.com/ | Product |
| https://extensions.joomla.org/extensions/extension/living/education-a-culture/quiz-deluxe/ | Product |
| https://www.exploit-db.com/exploits/42589 | Exploit VDB Entry |
| https://www.vulncheck.com/advisories/joomla-component-quiz-deluxe-sql-injection | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-06-19 16:16
Updated : 2026-08-19 15:13
NVD link : CVE-2017-20257
Mitre link : CVE-2017-20257
CVE.ORG link : CVE-2017-20257
JSON object : View
Products Affected
joomplace
- quiz_deluxe
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
