---
id: CVE-2019-25759
title: Joomla! Component vBizz 1.0.7 SQL Injection
summary: >-
  Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that
  allows authenticated attackers to execute arbitrary SQL queries by injecting
  malicious code through the payid parameter. Attackers can submit POST requests
  to the…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'
cvssSource: cna
cwe:
  - CWE-89
vendor: Wdmtech
product: vBizz
affected:
  - vBizz 1.0.7
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-06-22T17:07:52.891878Z'
exploitAvailable: true
published: '2026-06-19'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:29.896Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2019-25759'
references:
  - url: 'https://www.exploit-db.com/exploits/46223'
    label: ExploitDB-46223
  - url: 'http://wdmtech.com/'
    label: Official Product Homepage
  - url: 'https://extensions.joomla.org/extensions/extension/marketing/crm/vbizz/'
    label: Product Reference
  - url: 'https://www.vulncheck.com/advisories/joomla-component-vbizz-sql-injection'
    label: 'VulnCheck Advisory: Joomla! Component vBizz 1.0.7 SQL Injection'
tags:
  - cve.org
  - exploit-available
epss: 0.00405
epssPercentile: 0.32299
ingestedAt: '2026-10-01T15:48:17.880Z'
---

## Overview

Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the payid parameter. Attackers can submit POST requests to the employee management interface with crafted payid array values containing SQL commands to extract sensitive database information including version and database names.

## Affected

- `vBizz 1.0.7`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
