peter bassill · operator
$ cve CVE-2018-14592 JSON

CVE-2018-14592 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 3.1% (pctl 87)

Patch early

A public exploit exists.

Description

The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection within download.php.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.11% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2018-09-20
Last modified2026-06-17

Affected (2)

VendorProduct
cwjoomlacw article attachments free
cwjoomlacw article attachments pro

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD