SQL Injection Vulnerability in Joomla's JHotelReservation by Joomla
CVE-2019-25748
Key Information:
- Vendor
Cmsjunkie
- Status
- Vendor
- CVE Published:
- 19 June 2026
Badges
What is CVE-2019-25748?
Joomla JHotelReservation version 6.0.7 is susceptible to an SQL injection flaw that enables unauthenticated attackers to execute arbitrary SQL queries through the 'rooms' parameter. By sending specially crafted POST requests to the 'search-hotels' endpoint, attackers can manipulate the SQL execution and potentially extract sensitive database information, including backend version details. This vulnerability poses a significant risk, allowing unauthorized access to sensitive data, which can lead to further exploitation.
Affected Version(s)
JHotelReservation 6.0.7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
