CVE-2018-5994: SQL Injection
Published Feb 17, 2018
·Updated
SQL Injection exists in the JS Jobs 1.1.9 component for Joomla! via the zipcode parameter in a newest-jobs request, or the ta parameter in a viewresume request.
Affected Software
1 affected component
joomsky Js Jobs Joomla\!=1.1.9
Event History
Feb 17, 2018
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Data Sourced
via NVD·07:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2018-5994?
CVE-2018-5994 is a SQL Injection vulnerability that exists in the JS Jobs 1.1.9 component for Joomla!.
2
How severe is CVE-2018-5994?
CVE-2018-5994 has a severity rating of 9.8 (critical).
3
How does CVE-2018-5994 work?
CVE-2018-5994 allows an attacker to inject malicious SQL queries into the zipcode parameter in a newest-jobs request or the ta parameter in a view_resume request in the JS Jobs 1.1.9 component for Joomla!.
4
What is the affected software?
The affected software is Joomsky Js Jobs version 1.1.9 running on Joomla!.
5
Is there a fix for CVE-2018-5994?
To fix CVE-2018-5994, it is recommended to update the JS Jobs component to a version that is not affected by this vulnerability.