Executive brief
CMSJunkie J-ClassifiedsManager is a Joomla extension used to create professional classified advertisement websites. A security flaw allows unauthenticated attackers to access and extract sensitive information from the website's database. This could lead to the exposure of user credentials, site configuration details, and other private data, potentially compromising the entire web platform.
Technical details
An SQL injection vulnerability exists in the J-ClassifiedsManager component (version 3.0.5 and below) for Joomla. The flaw is located within the 'displayads' component, specifically failing to properly sanitize the 'categorySearch', 'adType', and 'citySearch' POST parameters. An unauthenticated remote attacker can send crafted SQL payloads to these parameters to perform out-of-band or error-based data extraction. This allows for the retrieval of sensitive information from the underlying database, such as database names, version information, and user tables. While the vulnerability was publicly disclosed with a proof-of-concept in 2019, it was formally assigned a CVE in 2026.
Affected products
- CMSJunkie J-ClassifiedsManager 3.0.5 and earlier
Timeline
- 2019-01-23: disclosed: Initial exploit code published on Exploit-DB
- 2026-06-19: advisory: CVE-2019-25751 published by VulnCheck and NVD