Executive brief
vAccount is an accounting and financial management extension for the Joomla content management system. A security flaw in this component allows unauthorized individuals to access and extract sensitive information from the website's database. This could lead to the exposure of financial records, customer data, and technical details about the server's configuration.
Technical details
An SQL injection vulnerability exists in the vAccount component (version 2.0.2) for Joomla. The flaw is located within the 'vid' parameter of the 'vaccount-dashboard/expense' endpoint. An unauthenticated remote attacker can exploit this by sending specially crafted GET requests containing malicious SQL payloads. Successful exploitation allows the attacker to execute arbitrary SQL commands, enabling the extraction of sensitive database information such as database names, versions, and potentially administrative credentials or financial data. The vulnerability is classified as CWE-89.
Affected products
- Wdmtech vAccount 2.0.2
Timeline
- 2026-06-19: advisory: NVD publication date