---
id: CVE-2017-20266
title: Joomla SP Movie Database 1.3 SQL Injection via searchword
summary: >-
  Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that
  allows unauthenticated attackers to execute arbitrary SQL queries by injecting
  malicious code through the searchword parameter. Attackers can send GET
  requests to …
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'
cvssSource: cna
cwe:
  - CWE-89
vendor: Joomshaper
product: SP Movie Database
affected:
  - sp_movie_database 1.3
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-06-22T19:38:53.370867Z'
exploitAvailable: true
published: '2026-06-19'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:05.902Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2017-20266'
references:
  - url: 'https://www.exploit-db.com/exploits/42502'
    label: ExploitDB-42502
  - url: 'http://joomshaper.com/'
    label: Official Product Homepage
  - url: >-
      https://extensions.joomla.org/extensions/extension/directory-a-documentation/directory/sp-movie-database/
    label: Product Reference
  - url: >-
      https://www.vulncheck.com/advisories/joomla-sp-movie-database-sql-injection-via-searchword
    label: >-
      VulnCheck Advisory: Joomla SP Movie Database 1.3 SQL Injection via
      searchword
tags:
  - cve.org
  - exploit-available
epss: 0.00492
epssPercentile: 0.40013
ingestedAt: '2026-10-01T15:48:17.890Z'
---

## Overview

Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the searchword parameter. Attackers can send GET requests to the searchresults view with crafted SQL payloads in the searchword parameter to extract sensitive database information.

## Affected

- `sp_movie_database 1.3`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
