Junglewise Threat Intelligence

CVE-2017-20255: Joombooking JB Visa SQL injection in visatype parameter

CVE-2017-20255 · Severity: high · CVSS 8.2 · Published 2026-06-19

Executive brief

JB Visa is a Joomla extension used for managing visa applications and travel bookings. A security flaw allows unauthenticated attackers to access the underlying database, potentially leading to the theft of sensitive customer information, administrative credentials, and other private site data. This could result in a total compromise of the booking system's data integrity and confidentiality.

Technical details

An SQL injection vulnerability exists in the JB Visa component (version 1.0) for Joomla. The flaw is located in the 'visatype' parameter within the 'com_bookpro' component when accessed via index.php. An unauthenticated remote attacker can exploit this by sending specially crafted GET requests (e.g., using the view=popup parameter) to execute arbitrary SQL commands. This allows for the extraction of sensitive information from the database, including user credentials and table contents. The extension has been unpublished from the Joomla Extensions Directory due to this vulnerability.

Affected products

  • Joombooking (HVTech) JB Visa 1.0

Timeline

  • 2017-12-17: disclosed: Initial exploit published on Exploit-DB
  • 2026-06-19: advisory: CVE published and NVD record created

References