Unrated severityNVD Advisory· Published Jun 19, 2026
Joomla JoomRecipe 1.0.4 Component Blind SQL Injection via search_author
CVE-2017-20277
Description
Joomla JoomRecipe 1.0.4 component contains a blind SQL injection vulnerability in the search_author parameter on the search results page. Attackers can inject SQL code through POST requests to the search endpoint to extract database information using boolean-based blind SQL injection techniques.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: =1.0.4
Patches
Vulnerability mechanics
References
4- www.exploit-db.com/exploits/42347mitreexploit
- www.vulncheck.com/advisories/joomla-joomrecipe-component-blind-sql-injection-via-search-authormitrethird-party-advisory
- joomboost.commitreproduct
- extensions.joomla.org/extensions/extension/vertical-markets/food-a-beverage/joomrecipe/mitreproduct
News mentions
1- Joomla!: 25 Component Vulnerabilities, Mostly SQLi, Disclosed in Single-Day BatchVypr Intelligence · Jun 19, 2026