First published: Tue Feb 25 2025(Updated: )
A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the country management area in backend.
Credit: security@joomla.org
Affected Software | Affected Version | How to fix |
---|---|---|
JoomShopping | >=1.0.0<1.4.3 | |
JoomShopping | >=1.0.0<=5.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22211 has been categorized as a high severity vulnerability due to the potential for authenticated attackers to execute arbitrary SQL commands.
To mitigate CVE-2025-22211, upgrade the JoomShopping component to version 1.4.4 or higher to eliminate the SQL injection vulnerability.
Authenticated users with administrator privileges using JoomShopping versions 1.0.0 to 1.4.3 are at risk of exploitation of CVE-2025-22211.
CVE-2025-22211 can be exploited via SQL injection attacks, allowing execution of arbitrary SQL commands against the database.
If upgrading is not possible, it is recommended to restrict access to the backend country management area to trusted administrators only as a temporary workaround.