Impact
The Joomla extension EDocman is vulnerable to an unauthenticated blind SQL injection. Attackers can send specially crafted requests to affected EDocman endpoints without any authentication, which enables the execution of arbitrary SQL statements against the backend database. The vulnerability exists in all EDocman versions lower than 3.9 and can be leveraged to read, modify, or delete data stored in the database. Classified as CWE‑89, the flaw carries a CVSS score of 8.7.
Affected Systems
All sites running the joomdonation.com EDocman extension for Joomla version lower than 3.9 are vulnerable. Sites using version 3.9 or later are not affected. The extension serves as a Joomla download manager and is widely used across Joomla CMS installations.
Risk and Exploitability
The flaw is exploitable via normal web requests to EDocman endpoints on versions lower than 3.9, meaning an attacker only needs to send crafted input; no authentication is required. The vulnerability carries a CVSS score of 8.7, indicating high severity, while the EPSS score of <1% suggests a very low probability of active exploitation at present. The vulnerability is not listed in CISA KEV. Given the unauthenticated nature and potential to compromise all data in the database, the overall risk remains notable for affected deployments.
OpenCVE Enrichment