Junglewise Threat Intelligence

CVE-2019-25752: Cmsjunkie J-BusinessDirectory SQL injection in categories.getCategories

CVE-2019-25752 · Severity: high · CVSS 8.2 · Published 2026-06-19

Vendors: Cmsjunkie.

Executive brief

A vulnerability exists in J-BusinessDirectory, a popular Joomla extension used to create business listings and service marketplaces. An unauthenticated attacker can exploit this flaw to access the website's underlying database. This could lead to the theft of sensitive information, including customer data, site configurations, and database schema details.

Technical details

An SQL injection vulnerability exists in the J-BusinessDirectory component (version 4.9.7) for Joomla! due to improper neutralization of the 'type' parameter in the 'categories.getCategories' task. A remote, unauthenticated attacker can exploit this by sending a specially crafted GET request to index.php with UNION-based SQL statements. Successful exploitation allows the attacker to execute arbitrary SQL queries, enabling the extraction of sensitive database information such as schema names and table data. The vulnerability is identified as CWE-89.

Affected products

  • Cmsjunkie J-BusinessDirectory 4.9.7

Timeline

  • 2019-01-23: disclosed: Exploit published on Exploit-DB
  • 2026-06-19: advisory: NVD publication date

References