Junglewise Threat Intelligence

CVE-2019-25756: Wdmtech vAccount SQL injection in vaccount-dashboard

CVE-2019-25756 · Severity: high · CVSS 8.2 · Published 2026-06-19

Vendors: Wdmtech.

Executive brief

vAccount is an accounting and financial management extension for the Joomla content management system. A security flaw in this component allows unauthorized individuals to access and extract sensitive information from the website's database. This could lead to the exposure of financial records, customer data, and technical details about the server's configuration.

Technical details

An SQL injection vulnerability exists in the vAccount component (version 2.0.2) for Joomla. The flaw is located within the 'vid' parameter of the 'vaccount-dashboard/expense' endpoint. An unauthenticated remote attacker can exploit this by sending specially crafted GET requests containing malicious SQL payloads. Successful exploitation allows the attacker to execute arbitrary SQL commands, enabling the extraction of sensitive database information such as database names, versions, and potentially administrative credentials or financial data. The vulnerability is classified as CWE-89.

Affected products

  • Wdmtech vAccount 2.0.2

Timeline

  • 2026-06-19: advisory: NVD publication date

References