CVE-2025-49484: Extension - joomsky.com - SQL injection in JS jobs component version 1.1.5 - 1.4.1 for Joomla
Published Jul 18, 2025
·Updated
A SQL injection vulnerability in the JS Jobs plugin versions 1.0.0-1.4.1 for Joomla allows low-privilege users to execute arbitrary SQL commands via the 'cvid' parameter in the employee application feature.
Affected Software
1 affected component
Joomla JS Jobs>=1.0.0<=1.4.1, >=1.1.5<=1.4.1
Event History
Jul 18, 2025
CVE Published
via MITRE·09:51 AM
Data Sourced
via MITRE·09:51 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Jul 22, 2025
Exploit Published
12:00 AM
Known Exploited
10:48 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-49484?
The severity of CVE-2025-49484 is rated as high due to the potential for low-privilege users to execute arbitrary SQL commands.
2
How do I fix CVE-2025-49484?
To fix CVE-2025-49484, update the JS Jobs plugin to version 1.4.2 or higher.
3
Which versions of the JS Jobs plugin are affected by CVE-2025-49484?
CVE-2025-49484 affects JS Jobs plugin versions from 1.0.0 to 1.4.1.
4
Who can exploit CVE-2025-49484?
Low-privilege users are able to exploit CVE-2025-49484 due to insufficient input validation.
5
What impact does CVE-2025-49484 have on Joomla installations?
CVE-2025-49484 allows unauthorized SQL command execution, potentially compromising Joomla installations.