Critical severity9.1NVD Advisory· Published Mar 29, 2019· Updated Jun 17, 2026
CVE-2019-9918
CVE-2019-9918
Description
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Input does not get validated and queries are not written in a way to prevent SQL injection. Therefore arbitrary SQL-Statements can be executed in the database.
Affected products
4- Range: = 1.2.2
- cpe:2.3:a:harmistechnology:je_messenger:1.2.2:*:*:*:*:joomla\!:*:*
- Range: <=1.2.2
- Range: <=1.2.2
Patches
Vulnerability mechanics
References
2- extensions.joomla.org/extension/je-messenger/nvdProductThird Party Advisory
- github.com/azd-cert/CVE/blob/master/CVEs/CVE-2019-9918.mdnvdThird Party Advisory
News mentions
0No linked articles in our index yet.