CVE-2019-25751

HIGH

Joomla J-ClassifiedsManager 3.0.5 SQL Injection

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25751. PoCs published by Ihsan Sencan.

AI-analyzed exploit summary This is a functional SQL injection exploit for Joomla! Component J-ClassifiedsManager 3.0.5. The PoC demonstrates how to inject malicious SQL payloads via the 'citySearch' parameter in a POST request, leading to potential data exfiltration or manipulation.

Description

Joomla Component J-ClassifiedsManager 3.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters. Attackers can submit crafted SQL payloads in the categorySearch, adType, and citySearch parameters to the displayads component to extract sensitive database information including usernames, databases, and version details.

Exploits (1)

exploitdb WORKING POC
by Ihsan Sencan · textwebappsphp
https://www.exploit-db.com/exploits/46231

This is a functional SQL injection exploit for Joomla! Component J-ClassifiedsManager 3.0.5. The PoC demonstrates how to inject malicious SQL payloads via the 'citySearch' parameter in a POST request, leading to potential data exfiltration or manipulation.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Joomla! Component J-ClassifiedsManager 3.0.5
No auth needed
Prerequisites: Access to the target Joomla instance with the vulnerable component installed
devstral-2 · analyzed Jun 19, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-46231
https://www.exploit-db.com/exploits/46231
Product product
Official Product Homepage
http://cmsjunkie.com/
Third Party Advisory third-party-advisory
VulnCheck Advisory: Joomla J-ClassifiedsManager 3.0.5 SQL Injection
https://www.vulncheck.com/advisories/joomla-j-classifiedsmanager-sql-injection

Scores

CVSS v3 8.2
EPSS 0.0037
EPSS Percentile 28.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
Cmsjunkie/ClassifiedsManager 3.0.5
Published Jun 19, 2026
Tracked Since Jun 19, 2026