Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code through profile fields and POST parameters. Attackers can inject script payloads in profile information fields like Address that execute when users visit the profile, or submit SQL injection payloads via the phone_no parameter to the user_setting endpoint to manipulate database queries.
Metrics
Affected Vendors & Products
References
History
Sun, 17 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Joomlaextensions
Joomlaextensions joomla! Extension Ekrishta |
|
| Vendors & Products |
Joomlaextensions
Joomlaextensions joomla! Extension Ekrishta |
Sun, 17 May 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code through profile fields and POST parameters. Attackers can inject script payloads in profile information fields like Address that execute when users visit the profile, or submit SQL injection payloads via the phone_no parameter to the user_setting endpoint to manipulate database queries. | |
| Title | Joomla! EkRishta 2.10 Persistent XSS and SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-17T12:11:35.396Z
Reserved: 2026-05-17T11:44:19.182Z
Link: CVE-2018-25330
No data.
Status : Received
Published: 2026-05-17T13:16:44.573
Modified: 2026-05-17T13:16:44.573
Link: CVE-2018-25330
No data.
OpenCVE Enrichment
Updated: 2026-05-17T17:00:01Z