CVE-2025-2126
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-2126 is a newly disclosed critical vulnerability affecting the JoomlaUX JUX Real Estate 3.4.0 component on Joomla platforms. The issue lies in the file /extensions/realestate/index.php/properties/list/list-with-sidebar/realties of the component's GET Parameter Handler. An attacker can exploit this vulnerability by manipulating the title argument, leading to SQL injection. This attack can be initiated remotely, making it a significant threat. The vulnerability has been publicly disclosed, and the exploit is currently in use. Sadly, the vendor has not responded to the disclosure, leaving users potentially vulnerable.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- JUX Real Estate