DPCalendar-Ad

Welcome, Guest
Username Password: Remember me
Keyword

242: Security issue? - GCalendar Component "gcid
(1 viewing) (1) Guest
The issues with an arrow are solved, the issues with a question mark are bugs and the ones with the exclamation mark are enhancements.

TOPIC: 242: Security issue? - GCalendar Component "gcid

242: Security issue? - GCalendar Component "gcid 2 years, 5 months ago #3773

  • ecweb
  • OFFLINE
  • Fresh Boarder
  • Karma: 0
Hi,

Just come across a security advisory about GCalendar2.14.
Any comments on this? Advice of how to fix the issue?



DESCRIPTION: A vulnerability has been discovered in the GCalendar component for Joomla, which can be exploited by malicious people to conduct SQL injection attacks.

Input passed via the "gcid" parameter to index.php (when "option" is set to "com_gcalendar" and "view" is set to "event") is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.

The vulnerability is confirmed in version 2.1.4. Other versions may also be affected.
Last Edit: 2 years, 5 months ago by laoneo.
The topic has been locked.

Re:242: Security issue? GCalendar Component "gcid 2 years, 5 months ago #3774

  • laoneo
  • OFFLINE
  • Administrator
  • Posts: 510
  • Karma: 50
I wasn't aware of this

the fix will come soon.....
Last Edit: 2 years, 5 months ago by laoneo.
The topic has been locked.

Re:242: Security issue? GCalendar Component "gcid 2 years, 5 months ago #3777

  • laoneo
  • OFFLINE
  • Administrator
  • Posts: 510
  • Karma: 50
The topic has been locked.

Re:242: Security issue? GCalendar Component "gcid 2 years, 5 months ago #3782

  • laoneo
  • OFFLINE
  • Administrator
  • Posts: 510
  • Karma: 50
I couldn't reproduce the problem....do you have some steps to reproduce the problem?
The topic has been locked.

Re:242: Security issue? GCalendar Component "gcid 2 years, 5 months ago #3785

  • ecweb
  • OFFLINE
  • Fresh Boarder
  • Karma: 0
sorry, I haven't reproduced it yet - I'm no expert on sql injections so I probably won't be trying to do it.

However, I appreciate the fix you have provided and hope that will do the trick.
Thanks!
The topic has been locked.

Re:242: Security issue? GCalendar Component "gcid 2 years, 5 months ago #3789

  • laoneo
  • OFFLINE
  • Administrator
  • Posts: 510
  • Karma: 50
the following file can be extracted in the root of the joomla installation, it should fix it......

File Attachment:

File Name: com_gcalendar_sql_patch.zip
File Size: 1422
The topic has been locked.
Moderators: erichorne, Tanguy
Time to create page: 0.38 seconds
Total visitors:935678
Visitors a day:949
Free PageRank Checker