CVE-2018-25351

Vulnérabilités

CVE-2018-25351

Joomla! Component EkRishta 2.10 contains an error-based SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by i…

HIGH Extension Joomla — harmistechnology

Joomla! Component EkRishta 2.10 contains an error-based SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the username parameter. Attackers can submit POST requests to the login endpoint with SQL injection payloads in the username field to extract database information including user credentials and system details.

8.8 Élevée · CVSS 4.0

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Score retenu : NVD

SourceSévérité d'origineCVSS
NVDHIGH 8.8 (v4.0)
Produit
Extension Joomla — harmistechnology
Corrigée dans
Non précisée
Publiée
23/05/2026
Modifiée
20/07/2026
CWE
CWE-89
  • EkRishta — 2.10 – 2.10

Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.

  1. Détectée via nvd26/09/2026 09:34 UTC