Junglewise Threat Intelligence

CVE-2020-37224: JoomSky J2 JOBS SQL injection in sortby parameter

CVE-2020-37224 · Severity: high · CVSS 7.1 · Published 2026-05-13

Vendors: JoomSky.

Executive brief

JoomSky J2 JOBS (also known as JS Jobs), a recruitment and job board extension for the Joomla content management system, contains a security flaw. An attacker with a valid user account can execute unauthorized database commands to view sensitive information. This could lead to the exposure of private user data or internal site configurations.

Technical details

An authenticated SQL injection vulnerability exists in JoomSky J2 JOBS (JS Jobs) version 1.3.0 for Joomla. The flaw is located in the 'sortby' parameter within the administrator index component. By sending a specially crafted POST request to /administrator/index.php, an authenticated attacker can bypass input sanitization to execute arbitrary SQL commands. This allows for the extraction of sensitive data from the underlying database. The vulnerability is classified as CWE-89 and has been verified with public exploit code. Newer versions (e.g., 1.4.8) are available, though the specific patching version for this 2020 flaw is not explicitly detailed in the advisory.

Affected products

  • JoomSky J2 JOBS (JS Jobs) 1.3.0

Timeline

  • 2020-06-17: disclosed: Vulnerability discovered by Mehmet Kelepçe
  • 2020-07-07: other: Exploit published on Exploit-DB
  • 2026-05-13: advisory: NVD/VulnCheck advisory published

References