Executive brief
JoomSky J2 JOBS (also known as JS Jobs) is a job board extension for the Joomla content management system. A security flaw in version 1.3.0 allows a logged-in user with administrative access to execute unauthorized database commands. This could lead to the theft of sensitive information, including user credentials and site configuration data, potentially compromising the entire website.
Technical details
An authenticated SQL injection vulnerability exists in JoomSky J2 JOBS (JS Jobs) version 1.3.0. The flaw is located within the 'sortby' parameter handled by the administrator index (com_jsjobs). An attacker with authenticated access to the Joomla administrator panel can send specially crafted POST requests to manipulate backend SQL queries. This vulnerability (CWE-89) allows for the extraction of sensitive data from the database using automated tools like sqlmap. While the advisory mentions version 1.3.0, later versions such as 1.4.8 are available, though specific patch confirmation for this CVE in the changelog is not explicitly detailed in the provided text.
Affected products
- JoomSky J2 JOBS (JS Jobs) 1.3.0
Timeline
- 2020-06-17: other: Vulnerability discovered
- 2020-07-15: disclosed: Exploit published on Exploit-DB
- 2026-05-13: advisory: NVD/VulnCheck advisory published