High severity8.2NVD Advisory· Published Jun 19, 2026· Updated Aug 19, 2026
CVE-2017-20257
CVE-2017-20257
Description
Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the ajaxaction.flag_question task. Attackers can inject malicious SQL code via the stu_quiz_id or flag_quest parameters to manipulate database queries and extract sensitive information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=3.7.4
Patches
Vulnerability mechanics
References
4- www.exploit-db.com/exploits/42589nvdExploitVDB Entry
- www.vulncheck.com/advisories/joomla-component-quiz-deluxe-sql-injectionnvdThird Party Advisory
- joomplace.comnvdProduct
- extensions.joomla.org/extensions/extension/living/education-a-culture/quiz-deluxe/nvdProduct
News mentions
0No linked articles in our index yet.