vendor:
JUX Real Estate
by:
CraCkEr
6.1
CVSS
HIGH
SQL Injection
89 - 74 - 707
CWE
Product Name: JUX Real Estate
Affected Version From: 3.4.2000
Affected Version To: 3.4.2000
Patch Exists: NO
Related CWE: CVE-2025-2126
CPE: a:joomlaux:jux_real_estate:3.4.0
Platforms Tested: Windows 11 Pro
2025
JUX Real Estate 3.4.0 – SQL Injection
SQL injection vulnerability in JUX Real Estate 3.4.0 allows attackers to access sensitive data, modify data, and potentially disrupt the application, resulting in financial losses and reputational damage to the organization.
Mitigation:
To mitigate this vulnerability, input validation should be implemented to sanitize user-supplied data and the use of parameterized queries or prepared statements should be enforced.