Impact
An unauthenticated SQL injection flaw exists in the JooDatabase Lite extension for Joomla versions prior to 5.1.0. The extension uses the cid parameter directly in database queries without validation, allowing an attacker to inject malicious SQL code. This omission enables arbitrary database manipulation, resulting in loss of confidentiality, potential integrity violations, and possible disruption of service. The weakness aligns with CWE-89, which describes SQL injection-related defects.
Affected Systems
All Joomla sites that have installed the JooDatabase Lite extension from joodb.feenders.de and are running any version older than 5.1.0 are impacted. The vendor responsible for this component is Joodb.feenders.de, but the vulnerability is embedded in the extension itself rather than any core Joomla functionality.
Risk and Exploitability
The CVSS score of 9.3 denotes a critical level of severity, and while an EPSS score is not provided, the lack of exploitation probability data does not mitigate the inherent risk. The vulnerability is not yet listed in the CISA KEV catalog. Because the flaw is unauthenticated, an attacker can exploit it from any web-facing interface that processes the cid parameter, potentially without requiring user credentials or special privileges.
OpenCVE Enrichment