Junglewise Threat Intelligence

CVE-2019-25757: Wdmtech vWishlist SQL injection in vproductid and userid parameters

CVE-2019-25757 · Severity: high · CVSS 7.1 · Published 2026-06-19

Vendors: Wdmtech.

Executive brief

vWishlist is a Joomla extension that allows users to save and manage favorite products within a VirtueMart-powered online store. A security flaw in this extension allows logged-in users to perform unauthorized database queries. This could lead to the exposure of sensitive website information, including database structures and administrative data, potentially compromising the entire store's security.

Technical details

An SQL injection vulnerability exists in Wdmtech vWishlist version 1.0.1 for Joomla. The flaw is located within the handling of the 'vproductid' and 'userid' parameters during POST requests to the component. Because these inputs are not properly neutralized before being used in SQL commands, an authenticated attacker can inject malicious SQL payloads. Successful exploitation allows for the extraction of sensitive information from the database, such as version details and database names, using error-based or union-based techniques. The vulnerability requires a valid user session (authenticated access) but can be exploited remotely over the network.

Affected products

  • Wdmtech vWishlist 1.0.1

Timeline

  • 2019-01-23: disclosed: Initial exploit published on Exploit-DB
  • 2026-06-19: advisory: CVE published and NVD record created

References