CVE-2025-49467
A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered.
CRITICAL
JEvents
Composant
Source officielle
Description
A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible actions to list events by date ranges.
Sévérité
9.3
Critique · CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Amber
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | CRITICAL | 9.3 (v4.0) |
Produit et versions
- Produit
- JEvents
- Type
- Composant
- Corrigée dans
- Non précisée
- Publiée
- 12/06/2025
- Modifiée
- 17/06/2026
- CWE
- CWE-89
Versions concernées
- com_jevents — 1.0.0 – 3.6.82
- com_jevents — 3.6.83 – 3.6.87
Sources
- NVD CNA Joomla CVE-2025-49467 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:34 UTC