-
YooRecipe, All, SQL Injection
YooRecipe, All, 3rd party extension, SQL Injection
-
publisher, 3.0.19, XSS (Cross Site Scripting)
publisher, 3.0.19, 3rd party extension, XSS (Cross Site Scripting)
-
paGO Commerce, 2.5.9.0, SQL Injection
paGO Commerce, 2.5.9.0, 3rd party extension, SQL Injection
-
Social Chat, 1.5 and Below, SQL Injection Iacopo Guarneri
Social Chat, 1.5 and Below, 3rd party extension, SQL Injection Iacopo Guarneri
-
hwdplayer,4.2,SQL Injection
hwdplayer,4.2,SQL Injection
Possible abandonware also
-
Rapicode, Multiple Extensions, Back Door
Rapicode, nultiple extensions, current versions, back door
Extensions affected are:-
- Rapi Content Ticker
- Rapi Content Carousel
- Rapi Cookie Consent
- Rapi Countdown
- Rapi Preloader
- Rapi Loading Progress Bar
- Rapi Page Animate
At the moment the back door seems to be loading mining code, it can be used to load arbitrary scripts or other content from the developer's site.
We suggest that the extensions be treated as malicious and uninstalled.
Note that their other extensions may be affected too, we have not had the opportunity to test them all. If you are using them we suggest checking the code for any curl request to cdn.rapicode.com, or using your browser tools to check for any unexpected scripts being loaded.
-
Google Map Landkarten,4.2.3,SQL Injection
Google Map Landkarten from joomla-24.de, versions 4.2.3 and previous, SQL Injection
-
Fastball, SQL Injection
Fastball by Fastball Productions, versions yet to be determined but probably all, SQL Injection
-
File Download Tracker,3.0,SQL Injection
File Download Tracker by techsolsystem.com, 3.0, SQL Injection
-
SquadManagement,1.0.3,SQL Injection
SquadManagement by Lars Hildebrandt, versions 1.0.3 and previous, SQL Injection
-
JMS Music,1.1.1,SQL Injection
JMS Music by Joomasters, versions 1.1.1 and previous, SQL Injection
-
JS Autoz ,1.0.9,SQL Injection
JS Autoz by Joomsky.com, 1.0.9 and previous, SQL Injection
|