Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-2667 | A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'fieldfor' parameter in the GDPR Field feature. |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 04 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Joomsky
Joomsky js Jobs |
|
| CPEs | cpe:2.3:a:joomsky:js_jobs:*:*:*:*:*:joomla\!:*:* | |
| Vendors & Products |
Joomsky
Joomsky js Jobs |
Thu, 06 Feb 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 05 Feb 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Feb 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 04 Feb 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'fieldfor' parameter in the GDPR Field feature. | |
| Title | Extension - joomsky.com - SQL injection in JS jobs component version 1.1.5 - 1.4.2 for Joomla | |
| Weaknesses | CWE-89 | |
| References |
|
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2025-02-06T10:48:55.695Z
Reserved: 2025-01-01T04:33:02.764Z
Link: CVE-2025-22206
Updated: 2025-02-04T20:56:50.484Z
Status : Analyzed
Published: 2025-02-04T15:15:19.797
Modified: 2025-06-04T20:52:00.963
Link: CVE-2025-22206
No data.
OpenCVE Enrichment
No data.
EUVD