SQL Injection Vulnerability in JS Jobs Plugin for Joomla
CVE-2025-49484

8.7HIGH

Key Information:

Vendor
CVE Published:
18 July 2025

What is CVE-2025-49484?

A SQL injection flaw in the JS Jobs plugin for Joomla allows low-privilege users to craft and execute unauthorized SQL commands through the 'cvid' parameter in the employee application feature, potentially leading to data exposure and manipulation.

Affected Version(s)

JS Jobs component for Joomla 1.0.0-1.4.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adam Wallwork
.
CVE-2025-49484 : SQL Injection Vulnerability in JS Jobs Plugin for Joomla