First published: Sat Feb 15 2025(Updated: )
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'searchpaymentstatus' parameter in the Employer Payment History search feature.
Credit: security@joomla.org
Affected Software | Affected Version | How to fix |
---|---|---|
joomsky JS Jobs | >=1.1.5<=1.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22209 is classified as a high severity SQL injection vulnerability.
To fix CVE-2025-22209, upgrade the JS Jobs plugin to a version higher than 1.4.3.
CVE-2025-22209 affects authenticated users, specifically administrators using vulnerable versions of the JS Jobs plugin.
CVE-2025-22209 allows authenticated attackers to execute arbitrary SQL commands, which may compromise the database.
JS Jobs versions between 1.1.5 and 1.4.3 are vulnerable to CVE-2025-22209.