CVE-2025-22209: Extension - joomsky.com - SQL injection in JS jobs component version 1.1.5 - 1.4.3 for Joomla
Published Feb 15, 2025
·Updated
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'searchpaymentstatus' parameter in the Employer Payment History search feature.
Affected Software
2 affected components
Joomla JS Jobs>=1.1.5<=1.4.3
joomsky Js Jobs Joomla\!>=1.1.5<=1.4.3
Event History
Feb 15, 2025
CVE Published
via MITRE·08:10 AM
Data Sourced
via MITRE·08:10 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-22209?
CVE-2025-22209 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2025-22209?
To fix CVE-2025-22209, upgrade the JS Jobs plugin to a version higher than 1.4.3.
3
Who is affected by CVE-2025-22209?
CVE-2025-22209 affects authenticated users, specifically administrators using vulnerable versions of the JS Jobs plugin.
4
What impact does CVE-2025-22209 have on my system?
CVE-2025-22209 allows authenticated attackers to execute arbitrary SQL commands, which may compromise the database.
5
What versions of JS Jobs are vulnerable to CVE-2025-22209?
JS Jobs versions between 1.1.5 and 1.4.3 are vulnerable to CVE-2025-22209.