Joomla! before 3.7.1 contains a SQL injection vulnerability. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.
View the template here CVE-2017-8917.yaml
References:
https://developer.joomla.org/security-centre/692-20170501-core-sql-injection.html