CRITICAL

CVE-2019-9184

CVSS v3

9.8

CRITICAL

EPSS Score

22.5%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the product_option[] parameter.

Technical details

Published
2/26/2019

Frequently asked questions

What is CVE-2019-9184?

SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the product_option[] parameter.

Is CVE-2019-9184 actively exploited?

Active exploitation of CVE-2019-9184 has not been confirmed. The EPSS score is 22.5%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-9184?

CVE-2019-9184 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2019-9184 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.