SQL Injection Vulnerability in JS Jobs Plugin for Joomla
CVE-2025-22209
4.7MEDIUM
What is CVE-2025-22209?
A SQL injection vulnerability has been identified in the JS Jobs plugin for Joomla, specifically affecting versions 1.1.5 through 1.4.3. This vulnerability allows authenticated users, such as administrators, to manipulate the 'searchpaymentstatus' parameter in the Employer Payment History feature. By exploiting this weakness, attackers can execute arbitrary SQL commands, potentially compromising the database integrity and confidentiality.
Affected Version(s)
JS Jobs component for Joomla 1.1.5-1.4.3