Executive brief
EDocman, a popular document management extension for Joomla used by over 50,000 sites, contains a security vulnerability that allows unauthorized individuals to interact directly with the website's database. By exploiting this flaw, an attacker could potentially steal sensitive information, including user data and administrative credentials, without needing a password. This could lead to a full compromise of the website's data and unauthorized access to managed documents.
Technical details
A SQL injection vulnerability (CWE-89) exists in the EDocman extension for Joomla, affecting versions 1.0 through 3.8. The flaw allows an unauthenticated remote attacker to send specially crafted requests to the application, bypassing input sanitization to execute arbitrary SQL commands against the backend database. Successful exploitation could lead to the unauthorized disclosure of sensitive information, such as user credentials or configuration data. The issue is addressed in version 3.9, released on July 14, 2026.
Affected products
- joomdonation.com EDocman extension for Joomla 1.0-3.8
Timeline
- 2026-07-14: patched: Version 3.9 released to address the vulnerability.
- 2026-07-15: disclosed: CVE-2026-57832 published.