Junglewise Threat Intelligence

CVE-2019-25758: Wdmtech vBizz unrestricted file upload in employee view

CVE-2019-25758 · Severity: high · CVSS 8.8 · Published 2026-06-19

Vendors: Wdmtech.

Executive brief

vBizz is a business management extension for Joomla used for CRM, accounting, and project management. A security flaw allows registered users to upload malicious files to the server instead of legitimate profile pictures. This could allow an attacker to take full control of the website, potentially leading to data theft or a complete service outage.

Technical details

An unrestricted file upload vulnerability exists in the vBizz component (v1.0.7) for Joomla. The flaw is located in the 'employee' view endpoint, where the 'profile_pic' parameter fails to properly validate file extensions or content types during a POST request. An authenticated attacker can exploit this by uploading a PHP shell disguised as an image or directly as a .php file. Once uploaded to the web-accessible 'uploads' directory, the attacker can execute the script to achieve Remote Code Execution (RCE) with the privileges of the web server. A public exploit has been available since 2019.

Affected products

  • Wdmtech vBizz 1.0.7

Timeline

  • 2019-01-23: disclosed: Exploit published on Exploit-DB
  • 2026-06-19: advisory: CVE published to NVD

References

Related threats