SQL Injection Vulnerability in JS Jobs Plugin for Joomla
CVE-2025-22209

4.7MEDIUM

Key Information:

Vendor
CVE Published:
15 February 2025

What is CVE-2025-22209?

A SQL injection vulnerability has been identified in the JS Jobs plugin for Joomla, specifically affecting versions 1.1.5 through 1.4.3. This vulnerability allows authenticated users, such as administrators, to manipulate the 'searchpaymentstatus' parameter in the Employer Payment History feature. By exploiting this weakness, attackers can execute arbitrary SQL commands, potentially compromising the database integrity and confidentiality.

Affected Version(s)

JS Jobs component for Joomla 1.1.5-1.4.3

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adam Wallwork
.
CVE-2025-22209 : SQL Injection Vulnerability in JS Jobs Plugin for Joomla