← Vulnerability feed

Vulnerability record · CVE-2017-8917 · published 17 May 2017

CVE-2017-8917: Joomla! 3.7.x unauthenticated SQL injection in core component

Joomla · Joomla\!

Joomla! 3.7.x before 3.7.1 contains a SQL injection flaw in a core component that lets an attacker run arbitrary SQL commands. The record does not name the vulnerable component or the exact request parameter, but the flaw is remotely reachable without credentials and carries a critical CVSS score of 9.8. Because Joomla is widely deployed and public exploit code exists, unpatched sites are at immediate risk.

9.8 CVSS 3.0 Critical EPSS 100% · top 0.1% CWE-89 · SQL injection
9.8CVSS 3.0 base score, v2 7.5
100%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityUnauthenticated remote SQL injection with a 9.8 CVSS score, public exploit code and an EPSS probability above 0.99 makes this an urgent patch-first issue.

What it is

Joomla! 3.7.x before 3.7.1 contains a SQL injection flaw in a core component that lets an attacker run arbitrary SQL commands. The record does not name the vulnerable component or the exact request parameter, but the flaw is remotely reachable without credentials and carries a critical CVSS score of 9.8. Because Joomla is widely deployed and public exploit code exists, unpatched sites are at immediate risk.

Impact

An attacker can read, modify or delete data in the Joomla database, including user credential hashes and session data, and can potentially pivot to further compromise of the site or its host. Full confidentiality, integrity and availability impact is scored.

Attack surface

Reachable over the network via HTTP against the Joomla front end; the CVSS vector shows no privileges required and no user interaction, so the vulnerable endpoint is hit directly. The specific route and parameter are not given in the record.

Exploitation

Public exploit code is referenced on Exploit-DB, and EPSS is 0.99826 (99.959th percentile), indicating near-certain exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild federal tracking is available from this record.

What to do

  • Upgrade Joomla! to 3.7.1 or later immediately; this is the vendor-patched fix.
  • If immediate upgrade is impossible, take the site offline or place it behind a WAF rule blocking SQL injection patterns against Joomla endpoints.
  • Audit the database and Joomla admin accounts for unauthorized changes or added users after any exposure window.
  • Rotate database credentials and Joomla secret keys if compromise is suspected.
  • Verify no other Joomla 3.7.x instances remain in the environment, including staging and archived copies.

Detection

  • Search web server logs for requests to Joomla endpoints containing SQL keywords, UNION, or comment sequences from single source IPs.
  • Monitor database logs for anomalous SELECT, UNION, or stacked queries originating from the web application account.
  • Alert on creation of new Joomla super user accounts or unexpected changes to the users table.
  • Use file integrity monitoring on Joomla core and extension directories to catch post-exploitation webshell drops.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/98515 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1038522 Third Party AdvisoryVDB Entry
https://developer.joomla.org/security-centre/692-20170501-core-sql-injection.html PatchVendor Advisory
https://www.exploit-db.com/exploits/42033/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/44358/ ExploitThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/98515 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1038522 Third Party AdvisoryVDB Entry
https://developer.joomla.org/security-centre/692-20170501-core-sql-injection.html PatchVendor Advisory
https://www.exploit-db.com/exploits/42033/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/44358/ ExploitThird Party AdvisoryVDB Entry

Track CVE-2017-8917 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-10033PHPMailer isMail mailSend argument injection enables remote code executionPHPMailer before 5.2.18 fails to properly sanitize the Sender property in the mailSend function of the isMail transport, allowing a crafted backslash…KEVEPSS 100%analysed5.3CVE-2023-23752Joomla! webservice endpoints improper access checkJoomla! 4.0.0 through 4.2.7 contains an improper access check that allows unauthenticated access to webservice endpoints. Because the endpoints can e…KEVEPSS 100%analysed9.8CVE-2026-48902Joomla\! cleartext transmission vulnerabilityThe password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.EPSS 0.33%9.8CVE-2025-25226Joomla\! sql injection vulnerabilityImproper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected …EPSS 0.47%9.8CVE-2022-23795Joomla\! improper authentication vulnerabilityAn issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which …EPSS 1.1%9.8CVE-2022-23797Joomla\! sql injection vulnerabilityAn issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate filtering on the selected Ids on an request could resulted …EPSS 1.1%9.8CVE-2022-23799Joomla\! vulnerabilityAn issue was discovered in Joomla! 4.0.0 through 4.1.0. Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data.EPSS 1.2%9.8CVE-2010-1433Joomla\! unrestricted file upload vulnerabilityJoomla! Core is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied in…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2017-8917), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.