peter bassill · operator
$ cve CVE-2018-7315 JSON

CVE-2018-7315 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 2.7% (pctl 85)

Patch early

A public exploit exists.

Description

SQL Injection exists in the Ek Rishta 2.9 component for Joomla! via the gender, age1, age2, religion, mothertounge, caste, or country parameter.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS2.65% — more likely to be exploited than 85% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2018-02-22
Last modified2026-06-17

Affected (1)

VendorProduct
harmistechnologyek rishta

Public exploits

SourceTitleDate
exploit-dbJoomla! Component Ek Rishta 2.9 - SQL Injection2018-02-22

References

→ the Explorer  ·  watch your stack  ·  NVD