CVE-2016-15016 is a critical SQL injection vulnerability affecting mrtnmtth joomla_mod_einsatz_stats up to version 0.2, specifically within the getStatsByType function in helper.php when processing the 'year' argument. With a CVSS score of 9.8, this vulnerability allows unauthenticated attackers to achieve full compromise of confidentiality, integrity, and availability. There is no known active exploitation, publicly available exploit code, or Metasploit/Nuclei modules, though it has garnered significant community discussion. Upgrading to version 0.3 or applying patch 27c1b443cff45c81d9d7d926a74c76f8b6ffc6cb is recommended for remediation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.3CPE matchmatch criteria | cpe:2.3:a:joomla_mod_einsatz_stats_project:joomla_mod_einsatz_stats:*:*:*:*:*:joomla\!:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.