CVE-2019-25748: Joomla JHotelReservation 6.0.7 SQL Injection via search-hotels
Joomla JHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rooms parameter. Attackers can send POST requests to the search-hotels endpoint with crafted SQL payloads in the rooms parameter to extract sensitive database information including version details.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Joomla JHotelReservationto a version that resolves this vulnerability.Fixed in 6.0.7 - Compensating control
Block unauthenticated access to the Joomla JHotelReservation search-hotels endpoint (including POST requests that supply the rooms parameter) using a WAF or reverse-proxy rules until the SQL injection is remediated.
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25748?
The severity of CVE-2019-25748 is rated as high with a score of 8.2.
How do I fix CVE-2019-25748?
To fix CVE-2019-25748, update Joomla JHotelReservation to the latest version that addresses this SQL injection vulnerability.
What type of vulnerability is CVE-2019-25748?
CVE-2019-25748 is classified as an SQL injection vulnerability.
Can unprivileged users exploit CVE-2019-25748?
Yes, unprivileged attackers can exploit CVE-2019-25748 as it allows unauthenticated access to execute arbitrary SQL queries.
What is the impact of CVE-2019-25748 on Joomla JHotelReservation?
The impact of CVE-2019-25748 on Joomla JHotelReservation includes potential unauthorized data manipulation and access, as attackers can execute arbitrary SQL commands.