SQL Injection Vulnerability in Joomla! 3.7
Description: SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors. The vulnerability is caused by a new component, com_fields, which was introduced in version 3.7.
Impact: An SQL injection flaw that allows attackers to execute custom SQL code on affected systems and take over vulnerable sites.
Mitigation: Upgrade to version 3.7.1. Please check specific vendor advisory for more information.
Reference URL’s:
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8917
- https://www.joomla.org/announcements/release-news/5705-joomla-3-7-1-release.html
- https://blog.sucuri.net/2017/05/sql-injection-vulnerability-joomla-3-7.html
Recommended Posts
Press release April 2023: Situational Security Alerts from CIRT
21 Apr 2023 - Articles, English articles, News, Notice, Security Advisories & Alerts

Security Best Practices
29 Mar 2023 - Security Advisories & Alerts