Executive brief
vBizz is a business management extension for Joomla used for CRM, accounting, and project management. A security flaw allows registered users to upload malicious files to the server instead of legitimate profile pictures. This could allow an attacker to take full control of the website, potentially leading to data theft or a complete service outage.
Technical details
An unrestricted file upload vulnerability exists in the vBizz component (v1.0.7) for Joomla. The flaw is located in the 'employee' view endpoint, where the 'profile_pic' parameter fails to properly validate file extensions or content types during a POST request. An authenticated attacker can exploit this by uploading a PHP shell disguised as an image or directly as a .php file. Once uploaded to the web-accessible 'uploads' directory, the attacker can execute the script to achieve Remote Code Execution (RCE) with the privileges of the web server. A public exploit has been available since 2019.
Affected products
- Wdmtech vBizz 1.0.7
Timeline
- 2019-01-23: disclosed: Exploit published on Exploit-DB
- 2026-06-19: advisory: CVE published to NVD