Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used.
History

Wed, 04 Jun 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Joomla
Joomla joomla\!
CPEs cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*
Vendors & Products Joomla
Joomla joomla\!

Wed, 09 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Apr 2025 16:45:00 +0000

Type Values Removed Values Added
Description Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used.
Title [20250401] - Joomla Framework - SQL injection vulnerability in quoteNameStr method of Database package
Weaknesses CWE-89
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published: 2025-04-08T16:24:34.710Z

Updated: 2025-04-21T07:16:38.978Z

Reserved: 2025-02-04T14:17:18.261Z

Link: CVE-2025-25226

cve-icon Vulnrichment

Updated: 2025-04-09T14:32:11.563Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-08T17:15:35.453

Modified: 2025-06-04T20:50:08.840

Link: CVE-2025-25226

cve-icon Redhat

No data.