SQL Injection Vulnerability in RSMediaGallery for Joomla
CVE-2025-27753

6.5MEDIUM

Key Information:

Vendor
CVE Published:
5 June 2025

What is CVE-2025-27753?

A vulnerability exists in the RSMediaGallery component for Joomla versions 1.7.4 to 2.1.6, where unescaped user input is directly incorporated in SQL queries. This flaw allows authenticated attackers to exploit the system by injecting malicious SQL commands through vulnerable input fields within the dashboard. Successful exploitation can result in unauthorized access to the database, potential data leakage, or unauthorized changes to database records, posing a significant risk to user data and system integrity.

Affected Version(s)

RSMediaGallery component for Joomla 1.7.4-2.1.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kamil Szczurowski
Robert Kruczek
.