CVE-2025-25226
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 8, 2025
Updated: Apr 9, 2025
CWE ID 89
Summary
CVE-2025-25226 is a SQL injection vulnerability affecting the quoteNameStr method of a database package. The issue arises due to improper handling of identifiers. Notably, this protected method, which is not used in the original packages of the 2.x and 3.x branches, poses no risk when using the standard database class. However, classes that extend the affected class and utilize the vulnerable method may be susceptible to exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Joomla