CVE-2025-22206
MEDIUMJS Jobs 1.1.5-1.4.2 - Authenticated SQL Injection via GDPR Field Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-22206. PoCs published by AdamWallwork.
AI-analyzed exploit summary This repository contains a functional proof-of-concept for CVE-2025-22206, demonstrating a SQL injection vulnerability in the JS Jobs Joomla plugin via the 'fieldfor' parameter. The PoC includes a captured HTTP request and SQLMap commands to exploit the vulnerability.
Description
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'fieldfor' parameter in the GDPR Field feature.
Exploits (1)
This repository contains a functional proof-of-concept for CVE-2025-22206, demonstrating a SQL injection vulnerability in the JS Jobs Joomla plugin via the 'fieldfor' parameter. The PoC includes a captured HTTP request and SQLMap commands to exploit the vulnerability.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L