CVE-2025-22206

CVSS 3.1 Score 4.7 of 10 (medium)

Details

Published Feb 4, 2025
Updated: Feb 6, 2025
CWE ID 89

Summary

CVE-2025-22206 is a SQL injection vulnerability affecting the JS Jobs plugin versions 1.1.5-1.4.2 used with Joomla. This issue permits authenticated attackers, specifically administrators, to execute arbitrary SQL commands by exploiting the 'fieldfor' parameter within the GDPR Field feature. This vulnerability poses a significant risk, as SQL injection attacks can lead to unauthorized data access, modification, or even complete server takeover. To mitigate this risk, it is recommended that users update their JS Jobs plugin to the latest version as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share