Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code through profile fields and POST parameters. Attackers can inject script payloads in profile information fields like Address that execute when users visit the profile, or submit SQL injection payloads via the phone_no parameter to the user_setting endpoint to manipulate database queries.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 17 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Joomlaextensions
Joomlaextensions joomla! Extension Ekrishta |
|
| Vendors & Products |
Joomlaextensions
Joomlaextensions joomla! Extension Ekrishta |
Sun, 17 May 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code through profile fields and POST parameters. Attackers can inject script payloads in profile information fields like Address that execute when users visit the profile, or submit SQL injection payloads via the phone_no parameter to the user_setting endpoint to manipulate database queries. | |
| Title | Joomla! EkRishta 2.10 Persistent XSS and SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-17T12:11:35.396Z
Reserved: 2026-05-17T11:44:19.182Z
Link: CVE-2018-25330
No data.
Status : Received
Published: 2026-05-17T13:16:44.573
Modified: 2026-05-17T13:16:44.573
Link: CVE-2018-25330
No data.
OpenCVE Enrichment
Updated: 2026-05-17T17:00:01Z
Weaknesses