Joomla Event Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_registrationpro&view=category&id parameter containing SQL injection payloads to extract sensitive database information.
Metrics
Affected Vendors & Products
References
History
Wed, 15 Jul 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vcita
Vcita event Registration Calendar By Vcita |
|
| CPEs | cpe:2.3:a:vcita:event_registration_calendar_by_vcita:4.1.3:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Vcita
Vcita event Registration Calendar By Vcita |
Mon, 22 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 21 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Joomlashowroom
Joomlashowroom event Registration Pro Calendar |
|
| Vendors & Products |
Joomlashowroom
Joomlashowroom event Registration Pro Calendar |
Fri, 19 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla Event Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_registrationpro&view=category&id parameter containing SQL injection payloads to extract sensitive database information. | |
| Title | Joomla Event Registration Pro Calendar 4.1.3 SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-15T01:23:26.936Z
Reserved: 2026-06-19T15:07:50.439Z
Link: CVE-2017-20273
Updated: 2026-06-22T14:18:29.097Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-20T22:35:18Z