Impact
The vulnerability is a classic SQL injection flaw in the product_id parameter of the Bargain Product VM3 component for Joomla! Version 1.0. It allows unauthenticated attackers to inject arbitrary SQL code through GET requests to the brainy and alice views. The attacker can read, modify, or delete user data or other sensitive database information if the database account has sufficient privileges. No execution of arbitrary code outside the database context is described, so the impact is primarily data exposure.
Affected Systems
The flaw affects Joomla! sites that have the Weborange Bargain Product VM3 component installed, version 1.0. Administrators should verify whether this exact version is present on their content management system.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating high severity, and the EPSS score is currently not available, but given the ease of exploitation via a simple GET request and lack of authentication checks, the risk is high. The flaw is not listed in the CISA KEV catalog, but that does not reduce its threat; attackers could still target affected sites easily. The attack vector is most likely a direct, unauthenticated web request to the vulnerable parameter.
OpenCVE Enrichment