PT-2025-6942 · Joomla · Js Jobs

Adam Wallwork

·

Published

2025-02-15

·

Updated

2025-02-21

·

CVE-2025-22209

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: JS Jobs plugin versions 1.1.5 through 1.4.3 for Joomla
Description: A SQL injection issue allows authenticated attackers, with administrator privileges, to execute arbitrary SQL commands via the searchpaymentstatus parameter in the Employer Payment History search feature.
Recommendations: For JS Jobs plugin versions 1.1.5 through 1.4.3, consider disabling the Employer Payment History search feature until a patch is available to prevent exploitation of the SQL injection vulnerability. Restrict access to the searchpaymentstatus parameter to minimize the risk of arbitrary SQL command execution.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-22209

Affected Products

Js Jobs