Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12382 | A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the product management area in backend. |
Wed, 28 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Virtuemart
Virtuemart virtuemart |
|
| CPEs | cpe:2.3:a:virtuemart:virtuemart:*:*:*:*:*:joomla\!:*:* | |
| Vendors & Products |
Virtuemart
Virtuemart virtuemart |
Tue, 06 May 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 May 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 21 Apr 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the product management area in backend. | |
| Title | Extension - virtuemart.net - SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla | |
| Weaknesses | CWE-89 | |
| References |
|
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2025-05-07T04:36:46.068Z
Reserved: 2025-02-04T14:21:34.509Z
Link: CVE-2025-25228
Updated: 2025-05-06T20:06:22.915Z
Status : Analyzed
Published: 2025-04-21T08:15:29.603
Modified: 2025-05-28T15:49:49.080
Link: CVE-2025-25228
No data.
OpenCVE Enrichment
No data.
EUVD