PT-2025-4390 · Joomla · Js Jobs Plugin

·

CVE-2025-22206

·

Published

2025-02-04

·

Updated

2025-06-04

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions JS Jobs plugin versions 1.1.5 through 1.4.2 for Joomla
Description A SQL injection issue allows authenticated attackers, specifically administrators, to execute arbitrary SQL commands. This is achieved via the fieldfor parameter in the GDPR Field feature.
Recommendations For JS Jobs plugin versions 1.1.5 through 1.4.2, consider disabling the GDPR Field feature until a patch is available to prevent exploitation of the SQL injection vulnerability. Restrict access to the fieldfor parameter to minimize the risk of arbitrary SQL command execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-22206

Affected Products

Js Jobs Plugin