CVE-2019-25740
HIGH EPSS 24.5%
Published Jun 4, 20263w ago · Modified Jun 17, 20261w ago
7.1 CVSS 4.0
Published Jun 4, 2026 3w ago
Last Modified Jun 17, 2026 1w ago
Description
Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom userfield parameters. Attackers can send POST requests to the job.savejob task with path traversal sequences in the field_2 parameter to delete arbitrary files accessible to the web server.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope X
Threat Intelligence
EPSS Exploit Probability
24.5% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-22 Path Traversal Resource Mgmt
References 4
- exploit-db.com https://www.exploit-db.com/exploits/47281
- joomsky.com https://www.joomsky.com/
- joomsky.com https://www.joomsky.com/5/download/1
- vulncheck.com https://www.vulncheck.com/advisories/joomla-com-jsjobs-arbitrary-file-deletion
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.