VulnerabilityModified
CVE-2016-10114
SQL injection vulnerability in the "aWeb Cart Watching System for Virtuemart" extension before 2.6.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via vectors involving categorysearch and smartSearch.
CRITICAL 9.8EPSS 2.40%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SQL injection vulnerability in the "aWeb Cart Watching System for Virtuemart" extension before 2.6.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via vectors involving categorysearch and smartSearch.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.40% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- awebsupport/aweb cart watching system for virtuemart
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/95293
- https://github.com/qemm/joomlasqli
- https://vel.joomla.org/resolved/1897-aweb-cart-watching-system-2-6-0Third Party Advisory
- https://www.exploit-db.com/exploits/40973/
- http://www.securityfocus.com/bid/95293
- https://github.com/qemm/joomlasqli
- https://vel.joomla.org/resolved/1897-aweb-cart-watching-system-2-6-0Third Party Advisory
- https://www.exploit-db.com/exploits/40973/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.