CVE-2018-25330 - CVE House
Back to Database
Status published High CVE-2018-25330

Joomla! EkRishta 2.10 Persistent XSS and SQL Injection

Vulnerability Description

Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code through profile fields and POST parameters. Attackers can inject script payloads in profile information fields like Address that execute when users visit the profile, or submit SQL injection payloads via the phone_no parameter to the user_setting endpoint to manipulate database queries.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-25330

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Sina Kheirkhah || (Sina.For.Sec@gmail.com)

Affected Vendor

Joomlaextensions

View all reports →

Affected Software

Joomla! extension EkRishta
Vulnerable Versions:
2.10

Timeline

Official Publish: May 17th, 2026
Last Modified: May 18th, 2026
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Weaknesses (CWE)