CVE-2017-20272
Joomla Ultimate Property Listing 1.0.2 SQL Injection via sf_selectuser_id
Vexday Risk Score
41Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 8.8EPSS 0.2%KEV nãoPoC públicaNuclei —Metasploit —Patch —
Lifecycle
19 Jun 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
Joomla Ultimate Property Listing 1.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the sf_selectuser_id parameter. Attackers can send GET requests to index.php with the option=com_upl and view=propertylisting parameters to extract sensitive database information including table names and column structures.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
Faboba · Ultimate Property Listingpublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/42417unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.