---
id: CVE-2017-20253
title: Joomla! Component My Projects 2.0 SQL Injection
summary: >-
  Joomla! Component My Projects 2.0 contains an SQL injection vulnerability that
  allows unauthenticated attackers to execute arbitrary SQL queries by injecting
  malicious code through the VerAyari parameter. Attackers can craft requests to
  …
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'
cvssSource: cna
cwe:
  - CWE-89
vendor: Gegabyte
product: My Projects
affected:
  - my_projects 2.0
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-06-23T18:00:42.424406Z'
exploitAvailable: true
published: '2026-06-19'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:02.121Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2017-20253'
references:
  - url: 'https://www.exploit-db.com/exploits/43358'
    label: ExploitDB-43358
  - url: 'http://www.gegabyte.org/'
    label: Official Product Homepage
  - url: >-
      https://extensions.joomla.org/extensions/extension/directory-a-documentation/portfolio/my-projects/
    label: Product Reference
  - url: >-
      https://www.vulncheck.com/advisories/joomla-component-my-projects-sql-injection
    label: 'VulnCheck Advisory: Joomla! Component My Projects 2.0 SQL Injection'
tags:
  - cve.org
  - exploit-available
epss: 0.00492
epssPercentile: 0.40017
ingestedAt: '2026-10-01T15:48:17.892Z'
---

## Overview

Joomla! Component My Projects 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the VerAyari parameter. Attackers can craft requests to the component endpoint with SQL injection payloads to extract sensitive database information including credentials and system data.

## Affected

- `my_projects 2.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
