SQL Injection Vulnerability in JoomSky JS Job Manager Plugin by JoomSky
CVE-2025-32626

9.3CRITICAL

Key Information:

Vendor
Joomsky
Vendor
CVE Published:
17 April 2025

Summary

The JoomSky JS Job Manager plugin is susceptible to an SQL Injection vulnerability that allows an attacker to manipulate SQL queries by injecting harmful input. This situation could lead to unauthorized data access, data alteration, or even complete takeover of the database server. Affected versions include JS Job Manager from n/a up to and including 2.0.2. It is crucial for users to update to secure versions and follow best practices for preventing SQL Injection attacks.

Affected Version(s)

JS Job Manager <= 2.0.2

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

TrÆ°ÆĄng Hữu PhĂșc (truonghuuphuc) (Patchstack Alliance)
.