SQL Injection Vulnerability in Joomla Component vRestaurant 1.9.4
CVE-2019-25754
Key Information:
- Vendor
Wdmtech
- Status
- Vendor
- CVE Published:
- 19 June 2026
Badges
What is CVE-2019-25754?
The Joomla component vRestaurant version 1.9.4 is susceptible to an SQL injection flaw that permits unauthenticated attackers to execute arbitrary SQL statements. By injecting malicious payloads through the keysearch parameter in POST requests to the menu-listing-layout endpoint, attackers may gain access to sensitive data, including database table names. This vulnerability poses significant risks to data integrity and confidentiality, making it critical for users to apply security measures promptly.
Affected Version(s)
vRestaurant 1.9.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
