CVE-2019-25751: Joomla J-ClassifiedsManager 3.0.5 SQL Injection
Joomla Component J-ClassifiedsManager 3.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters. Attackers can submit crafted SQL payloads in the categorySearch, adType, and citySearch parameters to the displayads component to extract sensitive database information including usernames, databases, and version details.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25751?
CVE-2019-25751 has a high severity rating of 8.8.
How do I fix CVE-2019-25751?
To remediate CVE-2019-25751, update to the latest version of the Joomla J-ClassifiedsManager component.
What type of vulnerability is CVE-2019-25751?
CVE-2019-25751 is classified as an SQL injection vulnerability.
Who can be affected by CVE-2019-25751?
CVE-2019-25751 can be exploited by unauthenticated attackers targeting Joomla websites using the J-ClassifiedsManager component.
What systems are vulnerable to CVE-2019-25751?
The vulnerability affects Joomla Component J-ClassifiedsManager version 3.0.5.