First published: Mon Apr 21 2025(Updated: )
A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the product management area in backend.
Credit: security@joomla.org
Affected Software | Affected Version | How to fix |
---|---|---|
VirtueMart Joomla Ecommerce Edition CMS | >=1.0.0<=4.4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25228 is considered a critical vulnerability due to its potential for allowing authenticated attackers to execute arbitrary SQL commands.
To fix CVE-2025-25228, update the VirtueMart component to a version newer than 4.4.7.
Authenticated administrators using VirtueMart versions 1.0.0 to 4.4.7 on Joomla are affected by CVE-2025-25228.
CVE-2025-25228 is a SQL injection vulnerability impacting the product management area in the backend of VirtueMart.
Attackers exploiting CVE-2025-25228 can execute arbitrary SQL commands, potentially compromising the database and sensitive information.