Junglewise Threat Intelligence

CVE-2019-25753: Wdmtech VMap SQL injection in loadmarker task

CVE-2019-25753 · Severity: high · CVSS 8.2 · Published 2026-06-19

Vendors: Wdmtech.

Executive brief

Wdmtech VMap is a Joomla extension used to display database records and custom locations on Google Maps. A security flaw allows unauthorized individuals to run malicious database commands by sending a specially crafted web request. This could lead to the theft of sensitive information stored in the website's database, potentially compromising user data or site configuration.

Technical details

An SQL injection vulnerability exists in the VMap component (com_vmap) for Joomla, specifically within the 'loadmarker' task. The issue stems from improper neutralization of the 'latlngbound' parameter in GET requests sent to index.php. An unauthenticated remote attacker can exploit this by submitting malicious SQL payloads to manipulate backend database queries. Successful exploitation allows for unauthorized data extraction from the Joomla database. While the advisory focuses on version 1.9.6, later versions are available (e.g., 1.11.1), and users should verify if the fix is present in current releases.

Affected products

  • Wdmtech VMap 1.9.6

Timeline

  • 2026-06-19: advisory: NVD and VulnCheck published the vulnerability details.

References