An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate filtering on the selected Ids on an request could resulted into an possible SQL injection.
{
"extracted_events": [
{
"introduced": "3.0.0"
},
{
"last_affected": "3.10.6"
},
{
"introduced": "4.0.0"
},
{
"last_affected": "4.1.0"
}
],
"source": "CPE_RANGE",
"cpe": "cpe:2.3:a:joomla:joomla\\!:*:*:*:*:*:*:*:*"
}