CVE-2019-25753
HIGHJoomla! Component VMap 1.9.6 SQL Injection via loadmarker
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25753. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in Joomla! Component VMap 1.9.6 via the 'latlngbound' parameter. The crafted HTTP GET request injects SQL syntax, resulting in an XPATH syntax error, confirming the vulnerability.
Description
Joomla! Component VMap 1.9.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the latlngbound parameter. Attackers can send GET requests to index.php with the option=com_vmap&task=loadmarker parameters containing SQL injection payloads to manipulate database queries and extract sensitive information.
Exploits (1)
The exploit demonstrates a SQL injection vulnerability in Joomla! Component VMap 1.9.6 via the 'latlngbound' parameter. The crafted HTTP GET request injects SQL syntax, resulting in an XPATH syntax error, confirming the vulnerability.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N