Several vulnerabilities have been identified in third-party modules for Joomla:
- memorix: SQL injection in the "ThemeID" parameter
- informations : SQL injection in the "themeid" parameter
- Event Manager: SQL injection in the "cid" parameter
- Event Manager: remote file include allowing an authenticated attacker to upload HTML files to the server
Proofs-of-concept are available.
Vulnerable Products
Vulnerable Software: Joomla (OSM Development Team)
Solution
A temporary fix is available in Event Manager's development branch.