A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'fieldfor' parameter in the GDPR Field feature.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Jun 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Joomsky
Joomsky js Jobs |
|
CPEs | cpe:2.3:a:joomsky:js_jobs:*:*:*:*:*:joomla\!:*:* | |
Vendors & Products |
Joomsky
Joomsky js Jobs |
Thu, 06 Feb 2025 11:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Wed, 05 Feb 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 04 Feb 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Tue, 04 Feb 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'fieldfor' parameter in the GDPR Field feature. | |
Title | Extension - joomsky.com - SQL injection in JS jobs component version 1.1.5 - 1.4.2 for Joomla | |
Weaknesses | CWE-89 | |
References |
|

Status: PUBLISHED
Assigner: Joomla
Published: 2025-02-04T14:20:48.002Z
Updated: 2025-02-06T10:48:55.695Z
Reserved: 2025-01-01T04:33:02.764Z
Link: CVE-2025-22206

Updated: 2025-02-04T20:56:50.484Z

Status : Analyzed
Published: 2025-02-04T15:15:19.797
Modified: 2025-06-04T20:52:00.963
Link: CVE-2025-22206

No data.