CVE-2017-20277

Joomla JoomRecipe 1.0.4 component contains a blind SQL injection vulnerability in the search_author parameter on the search results page. Attackers can inject SQL code through POST requests to the search endpoint to extract database information using boolean-based blind SQL injection techniques.
Configurations

Configuration 1 (hide)

cpe:2.3:a:joomboost:joomla_joomrecipe:1.0.4:*:*:*:*:joomla\!:*:*

History

No history.

Information

Published : 2026-06-19 17:16

Updated : 2026-08-19 18:58


NVD link : CVE-2017-20277

Mitre link : CVE-2017-20277

CVE.ORG link : CVE-2017-20277


JSON object : View

Products Affected

joomboost

  • joomla_joomrecipe
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')