Impact
The DP Calendar extension for Joomla contains an authenticated, privileged blind SQL injection that is triggered when an article is saved with a content plugin. An attacker who holds the permission to update articles can inject SQL and read or modify arbitrary database contents, potentially elevating privileges or exfiltrating sensitive data.
Affected Systems
Vulnerable versions of the digital‑peak.com DP Calendar extension range from 5.5.0 to 10.11.2. Any site running these versions of the extension under Joomla and granting update rights to article users is subject to the fault, regardless of the site’s overall user base or deployment size.
Risk and Exploitability
With a CVSS score of 6.9 the flaw is classified as medium severity. The EPSS score is not published and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a logged‑in user with article update privileges, meaning the threat surface is limited to trusted accounts. However, when those premises are met, an attacker can inject blind queries to extract or alter database records, compromising confidentiality and integrity.
OpenCVE Enrichment