Vulnerabilities > Thephpfactory > Auction Factory > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-06-19 CVE-2018-17374 SQL Injection vulnerability in Thephpfactory Auction Factory 4.5.5
SQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order parameter.
network
low complexity
thephpfactory CWE-89
critical
9.8