Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla was discovered. The issue occurs within the submission export feature and requires administrative access to the export feature.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
https://rsjoomla.com/ cve-icon cve-icon
History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00398}

epss

{'score': 0.00433}


Thu, 12 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 11 Jun 2025 19:30:00 +0000

Type Values Removed Values Added
Description Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla was discovered. The issue occurs within the submission export feature and requires administrative access to the export feature.
Title Extension - rsjoomla.com - Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla
Weaknesses CWE-94
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N/S:N/AU:N/RE:L/U:Clear'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2025-06-12T15:18:38.814Z

Reserved: 2025-03-16T04:33:36.605Z

Link: CVE-2025-30085

cve-icon Vulnrichment

Updated: 2025-06-12T13:27:31.017Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-11T20:15:22.870

Modified: 2025-06-12T16:06:20.180

Link: CVE-2025-30085

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.