Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-25749

Опубликовано: 19 июн. 2026
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

Joomla J-CruisePortal 6.0.4 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the guest_adult parameter. Attackers can send POST requests to the cruises endpoint with crafted SQL payloads in the guest_adult parameter to extract sensitive database information or manipulate database records.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cmsjunkie:j-cruiseportal:6.0.4:*:*:*:*:joomla\!:*:*

EPSS

Процентиль: 18%
0.00263
Низкий

7.1 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.1
github
2 месяца назад

Joomla J-CruisePortal 6.0.4 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the guest_adult parameter. Attackers can send POST requests to the cruises endpoint with crafted SQL payloads in the guest_adult parameter to extract sensitive database information or manipulate database records.

EPSS

Процентиль: 18%
0.00263
Низкий

7.1 High

CVSS3

Дефекты

CWE-89