LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2019-25759

wdmtech · vbizz

Published
CVSS7.1
Severityhigh
WeaknessCWE-89
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Description

Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the payid parameter. Attackers can submit POST requests to the employee management interface with crafted payid array values containing SQL commands to extract sensitive database information including version and database names.

References

← Back to the CVE Tracker

Our coverage of CVE-2019-25759

No stories yet. This page updates automatically when we publish reporting that references CVE-2019-25759.