A high-severity SQL injection vulnerability tracked as CVE-2017-20263 affects Joomla! Component FocalPoint Pro/Free 1.2.3. Public disclosures show that unauthenticated attackers can send crafted GET requests to index.php using option=com_focalpoint, view=location, and a malicious id value to inject arbitrary SQL commands through the component’s location view. The flaw was originally publicly documented without a CVE and later cataloged as remotely exploitable with CVSS 4.0 8.8 and CVSS 3.1 8.2 ratings.
Successful exploitation could expose sensitive information stored in the backend database and may allow broader abuse depending on database permissions. Published guidance recommends updating the affected component, sanitizing the vulnerable id parameter, using parameterized queries, and limiting database account privileges to reduce impact if exploitation occurs.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The Joomla! FocalPoint Pro/Free 1.2.3 SQL injection flaw is identified as CVE-2017-20263 and described as remotely exploitable by unauthenticated attackers via a crafted GET request. The advisory rates the issue high severity and notes potential exposure of sensitive database information.
A publicly disclosed SQL injection vulnerability affecting Joomla! Component FocalPoint Pro / Free 1.2.3 was documented by Ihsan Sencan. The disclosure included a proof of concept showing exploitation through the location view id parameter in index.php.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourceexploit-db.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.