CVE-2018-25330: Joomla! EkRishta 2.10 Persistent XSS and SQL Injection
Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code through profile fields and POST parameters. Attackers can inject script payloads in profile information fields like Address that execute when users visit the profile, or submit SQL injection payloads via the phone_no parameter to the user_setting endpoint to manipulate database queries.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25330?
CVE-2018-25330 has been rated as a high-severity vulnerability due to its potential for persistent XSS and SQL injection attacks.
How do I fix CVE-2018-25330?
To fix CVE-2018-25330, you should update the Joomla! EkRishta extension to the latest version that addresses these vulnerabilities.
What types of attacks can be executed using CVE-2018-25330?
CVE-2018-25330 allows attackers to execute persistent cross-site scripting and SQL injection attacks.
Which software is affected by CVE-2018-25330?
CVE-2018-25330 affects the Joomla! EkRishta extension version 2.10.
How can attackers exploit CVE-2018-25330?
Attackers can exploit CVE-2018-25330 by injecting malicious code through profile fields and POST parameters.