CVE-2025-22208

CVE-2025-22208: Extension - joomsky.com - SQL injection in JS jobs component version 1.1.5 - 1.4.3 for Joomla

Vendor Joomsky.com
Product JS Jobs component for Joomla
Weakness CWE-89 · SQLi
Published February 15, 2025
Last update February 21, 2025

CVSS base score

What the vulnerability does

Description

A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'filter_email' parameter in the GDPR Erase Data Request search feature.

Key dates

Disclosure timeline

February 15, 2025 CVE published
February 21, 2025 Record updated