(#Several vulnerabilities have been identified in third-party plugins for Joomla:#- Msic: SQL injection in the "user_id" parameter#- aiContactSafe: SQL injection and file upload#- Huge-IT Image Gallery: cross-site scripting and SQL injection#- Huge-IT Portfolio Gallery: cross-site scripting and SQL injection#- Huge-IT Product Catalog: cross-site scripting and SQL injection#- Huge-IT Slideshow: cross-site scripting and SQL injection#- Weblinks: file upload#- Showdown: SQL injection in the "typeid" parameter#- Payplans: SQL injection in the "group_id" parameter)
Vulnerable Products
Vulnerable Software: Joomla (OSM Development Team) -
Solution
Versions 2.4.9, 3.0.10, 3.1.11, 3.2.7, 3.3.6, 3.4.1 and 3.5.0 of Payplans plugin fixes the vulnerability affecting it.