Description
In Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Hathor postinstall message.
Remediation
References
Related Vulnerabilities
WordPress 4.8.x Multiple Vulnerabilities (4.8 - 4.8.22)
Jenkins Use of Insufficiently Random Values Vulnerability (CVE-2020-2099)
Joomla! Core 1.6.x Cross-Site Scripting (1.6.0 - 1.6.6)
MySQL CVE-2013-3804 Vulnerability (CVE-2013-3804)
Apache HTTP Server NULL Pointer Dereference Vulnerability (CVE-2024-38477)