CVE-2025-49467

Vulnérabilités

CVE-2025-49467

A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered.

CRITICAL JEvents Composant Source officielle

A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible actions to list events by date ranges.

9.3 Critique · CVSS 4.0

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Amber

Score retenu : NVD

SourceSévérité d'origineCVSS
NVDCRITICAL 9.3 (v4.0)
Produit
JEvents
Type
Composant
Corrigée dans
Non précisée
Publiée
12/06/2025
Modifiée
17/06/2026
CWE
CWE-89
  • com_jevents — 1.0.0 – 3.6.82
  • com_jevents — 3.6.83 – 3.6.87

Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.

  1. Détectée via nvd26/09/2026 09:34 UTC