Back to Database
Status published
Unknown
CVE-2023-38044
Extension - hikashop.com - SQLi in HikaShop component for Joomla <= 4.7.2
Vulnerability Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-38044
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Vishal Saini and Siva Pothuluru S (Team Payatu)
References
More from hikashop.com
View All →CVE-2025-25225
Extension - hikashop.com - Privilege escalation vulnerability Hikashop component version 1.0.0 - 5.1.3 for Joomla
Unknown
0
CVE-2025-22210
Extension - hikashop.com - SQL injection in Hikashop component version 3.3.0 - 5.1.4 for Joomla
Unknown
0
CVE-2024-40746
Extension - hikashop.com - Stored cross site scripting vulnerability in Hikashop component for Joomla < 5.1.1
Unknown
0
Affected Vendor
hikashop.com
View all reports →Affected Software
HikaShop component for Joomla
Vulnerable Versions:
4.0.0-4.7.2
Timeline
Official Publish:
August 7th, 2023
Last Modified:
October 20th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
No vector data available