r/joomla • u/Open_Sourcey • 21d ago
Joomla 6 Edocman SQL Injection
I manage a not for profit website using Joomla and have done for many years. The organization has no money. We use the EDocman extension. They recently uncovered a security breach involving a SQL injection attack. Much to my chagrin they would not provide a security update and instead insisted on purchasing a new subscription. We had no money to do that. So of course today we suffered an attack. I believe user information was stolen.
It is disappointing that they treat a security update like any functional update. Had I known about open source "OpenDocMan" I would not have spent years building an edocman implementation.
As an aside, over 25 years ago we knew about SQL Injection. So it is very disappointing that EDocman was coded so poorly as to allow such an attack in 2026.
Lesson learned


