CVE-2025-49468

All FrameworksJoomlaCWE-89CVE-2025-49468

CVE-2025-49468

State: PUBLISHED · Published: 2025-06-13 · Updated: 2025-06-13 · Assigner: Joomla
Description
A SQL injection vulnerability in No Boss Calendar component before 5.0.7 for Joomla was discovered. The vulnerability allows remote authenticated users to execute arbitrary SQL commands via the id_module parameter.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2025/49xxx/CVE-2025-49468.json