---
id: CVE-2017-20256
title: Joomla Survey Force Deluxe 3.2.4 SQL Injection via invite Parameter
summary: >-
  Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that
  allows unauthenticated attackers to execute arbitrary SQL queries by injecting
  malicious code through the invite parameter. Attackers can send GET requests
  to …
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'
cvssSource: cna
cwe:
  - CWE-89
vendor: Joomplace
product: Survey Force Deluxe
affected:
  - survey_force_deluxe 3.2.4
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-06-23T02:10:41.527590Z'
published: '2026-06-19'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:03.370Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2017-20256'
references:
  - url: 'https://www.exploit-db.com/exploits/42606'
    label: ExploitDB-42606
  - url: 'http://joomplace.com/'
    label: Official Product Homepage
  - url: >-
      https://extensions.joomla.org/extensions/extension/contacts-and-feedback/surveys/survey-force-deluxe/
    label: Product Reference
  - url: >-
      https://www.vulncheck.com/advisories/joomla-survey-force-deluxe-sql-injection-via-invite-parameter
    label: >-
      VulnCheck Advisory: Joomla Survey Force Deluxe 3.2.4 SQL Injection via
      invite Parameter
tags:
  - cve.org
epss: 0.00492
epssPercentile: 0.40017
ingestedAt: '2026-10-01T15:48:17.892Z'
---

## Overview

Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the invite parameter. Attackers can send GET requests to the component with crafted SQL payloads in the invite parameter to extract sensitive database information.

## Affected

- `survey_force_deluxe 3.2.4`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
