CVE-2019-25759: Joomla! Component vBizz 1.0.7 SQL Injection
Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the payid parameter. Attackers can submit POST requests to the employee management interface with crafted payid array values containing SQL commands to extract sensitive database information including version and database names.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Joomla! vBizzto a version that resolves this vulnerability.Fixed in 1.0.7 - Compensating control
Block or restrict access to the employee management interface (the endpoint that processes POST requests containing the 'payid' array parameter) to trusted users/IPs until the SQL injection issue is remediated.
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25759?
The severity of CVE-2019-25759 is classified as high with a score of 7.1.
How do I fix CVE-2019-25759?
To fix CVE-2019-25759, update the vBizz Joomla Component to the latest version that addresses this SQL injection vulnerability.
What type of vulnerability is CVE-2019-25759?
CVE-2019-25759 is an SQL injection vulnerability affecting the vBizz Joomla Component.
Who is affected by CVE-2019-25759?
Authenticated users of the Joomla! Component vBizz version 1.0.7 are affected by CVE-2019-25759.
What can attackers do with CVE-2019-25759?
Attackers can execute arbitrary SQL queries by injecting malicious code via the payid parameter due to CVE-2019-25759.