PatchSiren cyber security CVE debrief
CVE-2017-20255 Joombooking CVE debrief
CVE-2017-20255 is a SQL injection vulnerability in Joomla! Component JB Visa 1.0. Unaffected product versions are unknown. The vulnerability allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the visatype parameter in GET requests to index.php with option=com_bookpro and view=popup parameters. This vulnerability has a CVSS score of 8.8, indicating high severity. Defenders should prioritize patching or mitigating this vulnerability to limit exposure to potential attacks. Disclosure: This article is AI-assisted and based on the supplied source corpus.
- Vendor
- Joombooking
- Product
- JB Visa
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-19
- Original CVE updated
- 2026-08-19
- Advisory published
- 2026-06-19
- Advisory updated
- 2026-08-19
Who should care
Defenders responsible for Joomla! installations, particularly those using Component JB Visa 1.0, should prioritize patching or mitigating this vulnerability. The high CVSS score of 8.8 indicates that this vulnerability poses significant risk. Security teams and administrators should review and address this vulnerability promptly to limit exposure.
Technical summary
CVE-2017-20255 is a SQL injection vulnerability in Joomla! Component JB Visa 1.0. The vulnerability exists in the visatype parameter of GET requests to index.php with option=com_bookpro and view=popup parameters. Attackers can inject malicious SQL code to extract sensitive database information, including credentials and table contents. The CVSS vector for this vulnerability is CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X.
Defensive priority
High priority due to CVSS score of 8.8 and potential for unauthenticated arbitrary SQL query execution.
Recommended defensive actions
- Inventory Joomla! installations for Component JB Visa 1.0
- Review official advisories for patching or mitigation guidance
- Apply vendor-supported remediation or patches
- Review compensating controls to limit exposure
- Monitor for suspicious activity related to this vulnerability
Evidence notes
Primary evidence for this vulnerability comes from the NVD and CVE.org records. The vulnerability affects Joomla! Component JB Visa 1.0, but specific details on affected product versions are limited. Defenders should verify the presence of this component in their Joomla! installations and review official sources for patching or mitigation guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-20255 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-20255
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-20255 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-20255
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://extensions.joomla.org/extensions/extension/vertical-markets/booking-a-reservations/jb-visa/
-
Source reference
Unverified legacy reference
URL: https://www.exploit-db.com/exploits/43350
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/joomla-component-jb-visa-sql-injection-via-visatype
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.