Joomla! Component JoomCRM 1.1.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the deal_id parameter. Attackers can send GET requests to index.php with option=com_joomcrm&view=contacts and inject SQL code in the deal_id parameter to extract sensitive database information including table names and schemas.
References
| Link | Resource |
|---|---|
| http://joomboost.com/ | Product |
| https://extensions.joomla.org/extensions/extension/marketing/crm/joomcrm/ | Product |
| https://www.exploit-db.com/exploits/46122 | Exploit VDB Entry |
| https://www.vulncheck.com/advisories/joomla-component-joomcrm-sql-injection-via-deal-id | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-06-19 18:16
Updated : 2026-08-21 14:39
NVD link : CVE-2019-25761
Mitre link : CVE-2019-25761
CVE.ORG link : CVE-2019-25761
JSON object : View
Products Affected
joomboost
- joomcrm
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
