A SQLi vulnerability in RSMediaGallery component 1.7.4 - 2.1.6 for Joomla was discovered. The vulnerability is due to the use of unescaped user-supplied parameters in SQL queries within the dashboard component. This allows an authenticated attacker to inject malicious SQL code through unsanitized input fields, which are used directly in SQL queries. Exploiting this flaw can lead to unauthorized database access, data leakage, or modification of records.
References
Link Providers
https://rsjoomla.com/ cve-icon cve-icon
History

Tue, 17 Jun 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 05 Jun 2025 13:30:00 +0000

Type Values Removed Values Added
Description A SQLi vulnerability in RSMediaGallery component 1.7.4 - 2.1.6 for Joomla was discovered. The vulnerability is due to the use of unescaped user-supplied parameters in SQL queries within the dashboard component. This allows an authenticated attacker to inject malicious SQL code through unsanitized input fields, which are used directly in SQL queries. Exploiting this flaw can lead to unauthorized database access, data leakage, or modification of records.
Title Extension - rsjoomla.com - A SQLi vulnerability RSMediaGallery component 1.7.4 - 2.1.6 for Joomla
Weaknesses CWE-89
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published: 2025-06-05T13:20:51.810Z

Updated: 2025-06-19T04:38:39.043Z

Reserved: 2025-03-06T04:34:05.523Z

Link: CVE-2025-27753

cve-icon Vulnrichment

Updated: 2025-06-17T20:12:32.780Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-05T14:15:31.550

Modified: 2025-06-17T21:15:37.440

Link: CVE-2025-27753

cve-icon Redhat

No data.