CVE-2019-25761Disclosure(joomboost / joomcrm)

LOWCVSS 7.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Joomla! Component JoomCRM 1.1.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the deal_id parameter. Attackers can send GET requests to index.php with option=com_joomcrm&view=contacts and inject SQL code in the deal_id parameter to extract sensitive database information including table names and schemas.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • joomcrm

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
joomcrm

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-20: 2Technical Details · 2026-06-20: 206-20
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2019-25761 Joomla! Component JoomCRM 1.1.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious co… https://www.cve.org/CVERecord?id=CVE-2019-25761

    Post summary

    The statement reports a newly disclosed SQL injection flaw in JoomCRM 1.1.1 that permits authenticated attackers to run arbitrary SQL commands.

    00010293
    57.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2019-25761 Joomla! Component JoomCRM 1.1.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious co… https://www.cve.org/CVERecord?id=CVE-2019-25761 ----- Traducción: La vulnerabilidad … http://infoflow.cloud`

    Post summary

    The post announces CVE-2019-25761, detailing an authenticated SQL injection in Joomla! Component JoomCRM 1.1.1 that permits arbitrary SQL execution, with no evidence of exploitation or remediation.

    0000034
    88 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjoomboostjoomcrm1.1.1joomla\!-

Explore more