Executive brief
Cmsjunkie JHotelReservation is a booking and management extension for Joomla websites used by hotels and resorts to handle online reservations. A security vulnerability in version 6.0.7 allows unauthorized individuals to bypass security controls and access the underlying database. This could lead to the theft of sensitive customer information, reservation details, and server configuration data, potentially damaging the business's reputation and operational security.
Technical details
An SQL injection vulnerability exists in the JHotelReservation component (version 6.0.7) for Joomla. The flaw is located in the 'search-hotels' endpoint, where the 'rooms' parameter in a POST request is not properly sanitized before being used in a database query. An unauthenticated remote attacker can exploit this by sending a crafted POST request containing SQL payloads (such as UNION SELECT statements). Successful exploitation allows the attacker to execute arbitrary SQL commands, enabling the extraction of sensitive data from the database, including version information and potentially user credentials or customer records. A public exploit has been documented in Exploit-DB.
Affected products
- Cmsjunkie JHotelReservation 6.0.7
Timeline
- 2019-01-23: disclosed: Vulnerability discovered and exploit published by Ihsan Sencan
- 2026-06-19: advisory: CVE published by VulnCheck and NVD