A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible actions to list events by date ranges.
References
Link Providers
https://jevents.net/ cve-icon cve-icon
History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.0004}

epss

{'score': 0.00043}


Thu, 12 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 12 Jun 2025 15:30:00 +0000

Type Values Removed Values Added
Description A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible actions to list events by date ranges.
Title Joomla Extension - jevents.net - SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/AU:Y/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published: 2025-06-12T15:18:32.804Z

Updated: 2025-06-12T15:52:20.609Z

Reserved: 2025-06-05T04:37:35.548Z

Link: CVE-2025-49467

cve-icon Vulnrichment

Updated: 2025-06-12T15:35:21.649Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-12T16:15:23.363

Modified: 2025-06-16T12:32:18.840

Link: CVE-2025-49467

cve-icon Redhat

No data.