HIGH
Joomla! Component vBizz 1.0.7 Remote Code Execution
Published Jun 19, 2026
8.7
HIGHCVSS 4.0
EPSS 1.00%
Description
Joomla! Component vBizz 1.0.7 contains an unrestricted file upload vulnerability that allows authenticated attackers to upload arbitrary PHP files by submitting malicious files through the profile_pic parameter. Attackers can upload PHP files via POST requests to the employee view endpoint and execute them from the uploads directory to achieve remote code execution.
Affected products
-
- Version 1.0.7StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://wdmtech.com/ product
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-20194 Advisory
- https://extensions.joomla.org/extensions/extension/marketing/crm/vbizz/ product
- https://www.exploit-db.com/exploits/46224 exploit
- https://www.vulncheck.com/advisories/joomla-component-vbizz-remote-code-execution third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://wdmtech.com/ | product | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-20194 | Advisory | |
| https://extensions.joomla.org/extensions/extension/marketing/crm/vbizz/ | product | |
| https://www.exploit-db.com/exploits/46224 | exploit | |
| https://www.vulncheck.com/advisories/joomla-component-vbizz-remote-code-execution | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jun 19, 2026
Updated Oct 1, 2026
Reserved Jun 19, 2026
Link CVE-2019-25758
CISA Vulnrichment
Updated Jun 22, 2026
ENISA EUVD
EUVD-2019-20194 Assigner VulnCheck
Published Jun 19, 2026
Updated Oct 1, 2026
Exploited since n/a
Link EUVD-2019-20194