PT-2025-9835 · Joomla · Convert Forms

Adam Wallwork

·

Published

2025-03-05

·

Updated

2025-03-14

·

CVE-2025-22212

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions ConvertForms component versions 1.0.0 through 4.4.9 for Joomla
Description A SQL injection issue in the ConvertForms component for Joomla allows authenticated attackers, specifically administrators, to execute arbitrary SQL commands. This exploitation occurs in the submission management area of the backend.
Recommendations For ConvertForms component versions 1.0.0 through 4.4.9, update to a version that contains a fix for this issue to prevent SQL injection attacks.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-22212

Affected Products

Convert Forms