PatchSiren cyber security CVE debrief
CVE-2017-20266 Joomshaper CVE debrief
CVE-2017-20266 is a high-severity SQL injection vulnerability in Joomla SP Movie Database 1.3. Unaunthenticated attackers can inject malicious SQL code through the searchword parameter in the searchresults view, allowing them to execute arbitrary SQL queries and potentially extract sensitive database information. This vulnerability has a CVSS score of 8.8, indicating a high level of severity. Defenders should prioritize patching or mitigating this vulnerability to prevent potential attacks.
- Vendor
- Joomshaper
- Product
- SP Movie Database
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-19
- Original CVE updated
- 2026-08-19
- Advisory published
- 2026-06-19
- Advisory updated
- 2026-08-19
Who should care
Defenders responsible for Joomla SP Movie Database installations, particularly those using version 1.3, should be aware of this vulnerability and take immediate action to patch or mitigate it. Additionally, security teams and administrators responsible for web applications and databases should be aware of the potential risks associated with this vulnerability.
Technical summary
The CVE-2017-20266 vulnerability is caused by a lack of proper input validation in the searchword parameter of the searchresults view in Joomla SP Movie Database 1.3. This allows unauthenticated attackers to inject malicious SQL code, potentially leading to arbitrary SQL query execution and sensitive database information disclosure. The vulnerability has a CVSS score of 8.8 and is classified as CWE-89.
Defensive priority
High priority due to high CVSS score and potential for sensitive data disclosure
Recommended defensive actions
- Inventory Joomla SP Movie Database installations to identify potential exposure
- Review official advisories and vendor documentation for patching or mitigation guidance
- Implement compensating controls, such as web application firewalls or intrusion detection systems, to detect and prevent potential attacks
- Monitor for suspicious activity and exception tracking to identify potential exploitation attempts
- Apply patches or updates provided by the vendor, if available
Evidence notes
The primary evidence for this vulnerability comes from the NVD and CVE.org records. The vulnerability affects Joomla SP Movie Database version 1.3. Defenders should verify the version and scope of affected installations from official sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-20266 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-20266
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-20266 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-20266
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://extensions.joomla.org/extensions/extension/directory-a-documentation/directory/sp-movie-database/
-
Source reference
Unverified legacy reference
URL: https://www.exploit-db.com/exploits/42502
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/joomla-sp-movie-database-sql-injection-via-searchword
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.