SQL Injection Vulnerability in JoomSky JS Help Desk Plugin
CVE-2026-24959
8.5HIGH
What is CVE-2026-24959?
The JS Help Desk plugin by JoomSky is susceptible to a SQL Injection vulnerability, which could allow attackers to execute arbitrary SQL commands through improper neutralization of special elements in SQL statements. This flaw impacts versions up to and including 3.0.1, potentially enabling blind SQL injection attacks that compromise the security of the web application.
Affected Version(s)
JS Help Desk 0 <= 3.0.1