Impact
The Vendor’s Sponsor Wall component version 8.0 for Joomla incorporates a classic SQL injection flaw that is triggered by an unsanitized wallid parameter. An attacker can send unauthenticated GET requests containing crafted SQL payloads to index.php with option=com_sponsorwall&task=click&wallid, allowing the execution of arbitrary database queries. This leads to the extraction of sensitive information, such as credentials and configuration data, thereby compromising the confidentiality of the site’s data.
Affected Systems
The vulnerable product is the Sponsor Wall extension published by Pulseextensions for Joomla. This analysis applies to all installations run with component version 8.0, regardless of the Joomla version in use.
Risk and Exploitability
The CVSS score of 7.1 classifies this vulnerability as high severity. The EPSS score is not available so the exact likelihood of exploitation cannot be quantified, but the exploit is public and simple, and the component is available to unauthenticated users. It is not listed in CISA’s KEV catalog. Attackers can exploit this flaw remotely via HTTP requests to the site’s front‑end, potentially gaining access to sensitive database contents and paving the way for further damage such as credential theft or privilege escalation.
OpenCVE Enrichment