VYPR

Smart Related Articles

by Smart Related Articles Project

CVEs (3)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-7628Cri0.649.80.00Apr 13, 2017The "Smart related articles" extension 1.1 for Joomla! has SQL injection in dialog.php (attacker must use search_cats variable in POST method to exploit this vulnerability).
CVE-2017-7626Med0.406.10.00Apr 13, 2017The "Smart related articles" extension 1.1 for Joomla! has XSS in dialog.php (n_art,type in GET Method).
CVE-2017-7627Med0.345.30.00Apr 13, 2017The "Smart related articles" extension 1.1 for Joomla! does not prevent direct requests to dialog.php (there is a missing _JEXEC check).