CVE-2020-37218
📛 CVE Title
(no title)
Description
Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hdwplayersearch parameter. Attackers can submit POST requests with crafted SQL payloads in the hdwplayersearch parameter to extract sensitive database information from the hdwplayer_videos table.
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- high
- CVSS score
- 8.2 / 10
- CVSS vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N- Effective score
- 8.2 / 10 HIGH source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2020-37218
- Linked Threat
- CVE-2020-37218 — CVE-2020-37218
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-05-13 16:16:33 UTC
- NVD last modified
- 2026-05-13 17:07:21 UTC
- NVD CVSS v3.1
- 8.2 / 10 HIGH source: disclosure@vulncheck.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N- Exploitability subscore
- 3.9 / 10
- Impact subscore
- 4.2 / 10
- EPSS score
- 0.0009 (probability of exploitation in next 30 days)
- EPSS percentile
- 25.25% vs all CVEs — higher = more likely to be exploited, as of 2026-05-24
NVD-assigned CWE(s):
CWE-89
(differs from the CNA list above)
NVD / KEV / EPSS data refreshed 2026-05-25 00:01 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2020-31219 - Assigner
- VulnCheck
- Published
- May 13, 2026, 2:22:30 PM
- Updated
- May 14, 2026, 6:28:34 PM
- EUVD base score (CVSS 4.0)
-
8.8 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N - EUVD-reported EPSS
- 0.0900
- Vendors
- Hdwplayer
- Products
-
com_hdwplayer (4.2)
ENISA description: Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hdwplayersearch parameter. Attackers can submit POST requests with crafted SQL payloads in the hdwplayersearch parameter to extract sensitive database information from the hdwplayer_videos table.
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (7)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://nvd.nist.gov/vuln/detail/CVE-2020-37218 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2020-37218 tenable:www.cve.org
- https://www.exploit-db.com/exploits/48242 tenable:www.exploit-db.com
- https://www.first.org/epss/ tenable:www.first.org
- https://www.hdwplayer.com/ tenable:www.hdwplayer.com
- https://www.hdwplayer.com/download/ tenable:www.hdwplayer.com
- https://www.vulncheck.com/advisories/joomla-com-hdwplayer-sql-injection-via-search-php tenable:www.vulncheck.com
NVD-tagged references (4)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://www.exploit-db.com/exploits/48242 disclosure@vulncheck.com
- https://www.hdwplayer.com/ disclosure@vulncheck.com
- https://www.hdwplayer.com/download/ disclosure@vulncheck.com
- https://www.vulncheck.com/advisories/joomla-com-hdwplayer-sql-injection-via-search-php disclosure@vulncheck.com
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:arstechnica.com
Google publishes exploit code threatening millions of Chromium users Google publishes exploit code before patch , reported 42 months earlier, is fixed.
2026-05-26 02:52 UTC -
web:blog.qualys.com
Vulnerability does not equal a patch , as such remediating a detected vulnerability requires deploying the right patches and, in some cases, making the right configuration changes. Using multiple tools to detect, map and deploy the right remediation actions is time consuming and will result in less efficient remediation results.
2026-05-26 02:52 UTC -
web:docs.tenable.com
Remediation and mitigation plans should be created based-off prioritization plans. Most legacy methods employ the CVSS to prioritize which vulnerabilities to remediate first. For example, a typical organizational policy is to remediate all vulnerabilities with a CVSS score of 7 and above.
2026-05-26 02:52 UTC -
web:oracle-base.com
The OPatch utility doesn't let you re-apply a patch already present, so it's quite easy to simplify the process by having a very similar process each quarter. Once I've got all the patches, I write a patching script for each product. For the database this includes OPatch and the latest database patches.
2026-05-26 02:52 UTC -
web:translate.google.com
Google's service, offered free of charge, instantly translates words, phrases, and web pages between English and over 100 other languages.
2026-05-26 02:52 UTC -
web:www.cortex.io
Patch management kicks in when you fix the problem: you download the patched version, test it in staging, and deploy to production. Vulnerability management identifies the risk; patch management reduces it. Effective patch management is a critical component of a comprehensive vulnerability management strategy.
2026-05-26 02:52 UTC -
web:www.mend.io
Practical guide to vulnerability remediation for developers & security teams. Learn how to detect, prioritize, fix , & monitor vulnerabilities.
2026-05-26 02:52 UTC -
web:www.microsoft.com
These Knowledge Base articles accompany all security updates and advisories, and include caveats or known issues with security updates. Additionally, support engineers document common concerns from customers in these KB articles. These Knowledge Base articles are published the Security Update Guide with each release on Patch Tuesday.
2026-05-26 02:52 UTC -
web:www.oracle.com
Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.
2026-05-26 02:52 UTC -
web:www.virustotal.com
VirusTotal is a platform for scanning files and URLs for viruses, malware, and other threats using multiple antivirus engines.
2026-05-26 02:52 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.