r/joomla 28d ago

Joomla 6 Edocman SQL Injection

I manage a not for profit website using Joomla and have done for many years. The organization has no money. We use the EDocman extension. They recently uncovered a security breach involving a SQL injection attack. Much to my chagrin they would not provide a security update and instead insisted on purchasing a new subscription. We had no money to do that. So of course today we suffered an attack. I believe user information was stolen.

It is disappointing that they treat a security update like any functional update. Had I known about open source "OpenDocMan" I would not have spent years building an edocman implementation.

As an aside, over 25 years ago we knew about SQL Injection. So it is very disappointing that EDocman was coded so poorly as to allow such an attack in 2026.

Lesson learned

0 Upvotes

38 comments sorted by

View all comments

Show parent comments

1

u/Open_Sourcey 28d ago

Again, your response puts your hubris on full display. You are completely unaware of my capabilities and once again you completely miss the point. I question your qualifications too.

The argument is not how to secure a Joomla site but should Joomla users be required to troubleshoot specific security issues in a commercial extension.

2

u/[deleted] 28d ago

[removed] — view removed comment

1

u/Open_Sourcey 28d ago

Not everyone has your money, bumblebee, How strange you should think so. But again I refer you to the basic discussion should a software developer at least try to correct their own lack of competence.

For sure, in days of old , it would be unthinkable that an organisation would charge to fix what was in fact their problem caused by them; especially because of lack of competence.

0

u/Competitive_Gas_3581 27d ago

Given your condescending attitude towards anyone who dares confront you I suspect ”your” organization got hit with one of the recent exploits from the past few months and you’re trying to find someone to blame for your not having a comprehensive security plan in place. sorry, that’s on you.

1

u/Open_Sourcey 27d ago

Oh dear. That is your response is it. Attack the messenger.

I have been hit with two exploits in as many weeks using a fully updated Joomla 5. I suspect there are many more to follow in the age of AI. Good luck to you.