PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-20255 Joombooking CVE debrief

CVE-2017-20255 is a SQL injection vulnerability in Joomla! Component JB Visa 1.0. Unaffected product versions are unknown. The vulnerability allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the visatype parameter in GET requests to index.php with option=com_bookpro and view=popup parameters. This vulnerability has a CVSS score of 8.8, indicating high severity. Defenders should prioritize patching or mitigating this vulnerability to limit exposure to potential attacks. Disclosure: This article is AI-assisted and based on the supplied source corpus.

Vendor
Joombooking
Product
JB Visa
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-19
Original CVE updated
2026-08-19
Advisory published
2026-06-19
Advisory updated
2026-08-19

Who should care

Defenders responsible for Joomla! installations, particularly those using Component JB Visa 1.0, should prioritize patching or mitigating this vulnerability. The high CVSS score of 8.8 indicates that this vulnerability poses significant risk. Security teams and administrators should review and address this vulnerability promptly to limit exposure.

Technical summary

CVE-2017-20255 is a SQL injection vulnerability in Joomla! Component JB Visa 1.0. The vulnerability exists in the visatype parameter of GET requests to index.php with option=com_bookpro and view=popup parameters. Attackers can inject malicious SQL code to extract sensitive database information, including credentials and table contents. The CVSS vector for this vulnerability is CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X.

Defensive priority

High priority due to CVSS score of 8.8 and potential for unauthenticated arbitrary SQL query execution.

Recommended defensive actions

  • Inventory Joomla! installations for Component JB Visa 1.0
  • Review official advisories for patching or mitigation guidance
  • Apply vendor-supported remediation or patches
  • Review compensating controls to limit exposure
  • Monitor for suspicious activity related to this vulnerability

Evidence notes

Primary evidence for this vulnerability comes from the NVD and CVE.org records. The vulnerability affects Joomla! Component JB Visa 1.0, but specific details on affected product versions are limited. Defenders should verify the presence of this component in their Joomla! installations and review official sources for patching or mitigation guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-20255 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-20255

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-20255 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-20255

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.