Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used.
History

Wed, 09 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Apr 2025 16:45:00 +0000

Type Values Removed Values Added
Description Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used.
Title [20250401] - Joomla Framework - SQL injection vulnerability in quoteNameStr method of Database package
Weaknesses CWE-89
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2025-04-21T07:16:38.978Z

Reserved: 2025-02-04T14:17:18.261Z

Link: CVE-2025-25226

cve-icon Vulnrichment

Updated: 2025-04-09T14:32:11.563Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-08T17:15:35.453

Modified: 2025-04-09T15:16:01.923

Link: CVE-2025-25226

cve-icon Redhat

No data.