Executive brief
A vulnerability exists in the J-MultipleHotelReservation extension for Joomla, which is used by businesses to manage hotel bookings and reservations. An unauthorized attacker can exploit this flaw to access the website's underlying database without needing a password. This could lead to the theft of sensitive customer information, booking records, and administrative data, potentially causing significant reputational damage and privacy violations.
Technical details
An unauthenticated SQL injection vulnerability exists in the J-MultipleHotelReservation component (version 6.0.7) for Joomla. The flaw is located in the 'search-hotels' endpoint, where the 'hotel_id' parameter is not properly sanitized before being used in a database query. An attacker can exploit this by sending a specially crafted POST request containing SQL UNION SELECT statements. Successful exploitation allows a remote attacker to extract sensitive information from the database, including table structures and record data. While the vulnerability was disclosed in 2019, it was formally assigned a CVE in 2026.
Affected products
- Cmsjunkie J-MultipleHotelReservation 6.0.7
Timeline
- 2019-01-23: disclosed: Initial exploit published on Exploit-DB
- 2026-06-19: advisory: CVE record published and NVD entry created