A SQL injection vulnerability in the JS Jobs plugin versions 1.0.0-1.4.1 for Joomla allows low-privilege users to execute arbitrary SQL commands via the 'cvid' parameter in the employee application feature.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 31 Jul 2025 16:30:00 +0000

Type Values Removed Values Added
References

Fri, 18 Jul 2025 11:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Jul 2025 10:00:00 +0000

Type Values Removed Values Added
Description A SQL injection vulnerability in the JS Jobs plugin versions 1.0.0-1.4.1 for Joomla allows low-privilege users to execute arbitrary SQL commands via the 'cvid' parameter in the employee application feature.
Title Extension - joomsky.com - SQL injection in JS jobs component version 1.1.5 - 1.4.1 for Joomla
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2025-07-31T16:19:36.148Z

Reserved: 2025-06-05T13:21:31.503Z

Link: CVE-2025-49484

cve-icon Vulnrichment

Updated: 2025-07-18T10:40:54.837Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-18T10:15:33.363

Modified: 2025-07-31T17:15:30.077

Link: CVE-2025-49484

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.