Impact
The Joomla component J-MultipleHotelReservation version 6.0.7 suffers from an SQL injection flaw that allows attackers to inject arbitrary SQL code through the hotel_id field. An unauthenticated attacker can send crafted POST requests to the search-hotels endpoint containing UNION SELECT statements, enabling the extraction of sensitive database information such as table names and column data.
Affected Systems
CMS Junkie’s J-MultipleHotelReservation Joomla extension, specifically version 6.0.7, is affected. This component is typically used on Joomla-based booking and reservation sites.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating a high severity level. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, suggesting current exploitation data is limited. Because the attack can be performed over a POST request without authentication, the potential for widespread exploitation exists, especially on sites that have not applied the component update yet.
OpenCVE Enrichment