CVE-2017-20260
Weborange Price Alert
Joomla! Component Price Alert 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the product_id parameter. Attackers can send requests to the subscribeajax view with crafted SQL payloads in the product_id parameter to extract sensitive database information including credentials and configuration data.
- CVSS
- 8.8
- EPSS
- 0.45% 36.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.20