CVE-2025-2126

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Mar 9, 2025
Updated: Mar 11, 2025
CWE ID 74
CWE ID 89

Summary

CVE-2025-2126 is a newly disclosed critical vulnerability affecting the JoomlaUX JUX Real Estate 3.4.0 component on Joomla platforms. The issue lies in the file /extensions/realestate/index.php/properties/list/list-with-sidebar/realties of the component's GET Parameter Handler. An attacker can exploit this vulnerability by manipulating the title argument, leading to SQL injection. This attack can be initiated remotely, making it a significant threat. The vulnerability has been publicly disclosed, and the exploit is currently in use. Sadly, the vendor has not responded to the disclosure, leaving users potentially vulnerable.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share