SQL Injection Vulnerability in ConvertForms for Joomla by Tassos
CVE-2025-22212

2.7LOW

Key Information:

Vendor

Tassos.gr

Vendor
CVE Published:
5 March 2025

What is CVE-2025-22212?

The ConvertForms component for Joomla contains a SQL injection vulnerability that allows authenticated administrators to send crafted SQL queries through the submission management area. This exploit could potentially lead to unauthorized access to the database, resulting in data manipulation or data theft.

Affected Version(s)

Convert Forms component for Joomla 1.0.0-4.4.9

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adam Wallwork
.