CVE-2018-25348: Joomla! Component Ek Rishta 2.10 SQL Injection via user_detail
Published May 23, 2026
·Updated
Joomla! Component Ek Rishta 2.10 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cid parameter. Attackers can send GET requests to the user_detail view with malicious cid values containing SQL commands to extract sensitive database information.
Affected Software
1 affected component
Joomla Joomla Component Ek Rishta=2.10
Event History
May 23, 2026
CVE Published
via MITRE·06:30 PM
Data Sourced
via MITRE·06:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-25348?
The severity of CVE-2018-25348 is rated high with a score of 8.2.
2
How can I fix CVE-2018-25348?
To fix CVE-2018-25348, update the Joomla! Component Ek Rishta to the latest version that addresses the SQL injection vulnerability.
3
What systems are affected by CVE-2018-25348?
CVE-2018-25348 affects the Joomla! Component Ek Rishta version 2.10.
4
What type of vulnerability is CVE-2018-25348?
CVE-2018-25348 is an SQL injection vulnerability.
5
Who can exploit CVE-2018-25348?
CVE-2018-25348 can be exploited by unauthenticated attackers.