Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Attackers can send POST requests to the administrator index with malicious 'sortby' values to extract sensitive database information.
Metrics
Affected Vendors & Products
References
History
Wed, 13 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Attackers can send POST requests to the administrator index with malicious 'sortby' values to extract sensitive database information. | |
| Title | Joomla J2 JOBS 1.3.0 Authenticated SQL Injection via sortby | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-13T14:22:35.017Z
Reserved: 2026-05-13T14:13:46.970Z
Link: CVE-2020-37224
No data.
Status : Deferred
Published: 2026-05-13T16:16:33.990
Modified: 2026-05-13T17:07:21.030
Link: CVE-2020-37224
No data.
OpenCVE Enrichment
Updated: 2026-05-13T16:45:44Z