PT-2025-4390 · Joomla · Js Jobs Plugin

Adam Wallwork

·

Published

2025-02-04

·

Updated

2025-06-04

·

CVE-2025-22206

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions JS Jobs plugin versions 1.1.5 through 1.4.2 for Joomla
Description A SQL injection issue allows authenticated attackers, specifically administrators, to execute arbitrary SQL commands. This is achieved via the fieldfor parameter in the GDPR Field feature.
Recommendations For JS Jobs plugin versions 1.1.5 through 1.4.2, consider disabling the GDPR Field feature until a patch is available to prevent exploitation of the SQL injection vulnerability. Restrict access to the fieldfor parameter to minimize the risk of arbitrary SQL command execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-22206

Affected Products

Js Jobs Plugin