CVE-2018-25330
📛 CVE Title
(no title)
Description
Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code through profile fields and POST parameters. Attackers can inject script payloads in profile information fields like Address that execute when users visit the profile, or submit SQL injection payloads via the phone_no parameter to the user_setting endpoint to manipulate database queries.
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- high
- CVSS score
- 8.2 / 10
- CVSS vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N- Effective score
- 8.2 / 10 HIGH source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2018-25330
- Linked Threat
- CVE-2018-25330 — CVE-2018-25330
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2018-21850 - Assigner
- VulnCheck
- Published
- May 17, 2026, 12:11:35 PM
- Updated
- May 18, 2026, 8:07:39 PM
- EUVD base score (CVSS 4.0)
-
8.8 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N - EUVD-reported EPSS
- 0.0200
- Vendors
- Joomlaextensions
- Products
-
Joomla! extension EkRishta (2.10)
- Aliases
-
GHSA-8g35-6gf9-rwcg
ENISA description: Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code through profile fields and POST parameters. Attackers can inject script payloads in profile information fields like Address that execute when users visit the profile, or submit SQL injection payloads via the phone_no parameter to the user_setting endpoint to manipulate database queries.
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (7)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://extensions.joomla.org/extensions/extension/living/dating-a-relationships/ek-rishta/ tenable:extensions.joomla.org
- https://nvd.nist.gov/vuln/detail/CVE-2018-25330 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2018-25330 tenable:www.cve.org
- https://www.exploit-db.com/exploits/44660 tenable:www.exploit-db.com
- https://www.first.org/epss/ tenable:www.first.org
- https://www.joomlaextensions.co.in/ tenable:www.joomlaextensions.co.in
- https://www.vulncheck.com/advisories/joomla-ekrishta-persistent-xss-and-sql-injection tenable:www.vulncheck.com
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:cvefeed.io
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
2026-05-26 02:56 UTC -
web:cybersecuritynews.com
No patch has been released yet; Microsoft has instead issued a multi-step manual mitigation guide while a formal security update is prepared. Windows BitLocker Security Bypass The vulnerability originates in WinRE's handling of the BootExecute registry value under HKLM\ControlSet001\Control\Session Manager.
2026-05-26 02:56 UTC -
web:nvd.nist.gov
An official website of the United States government Here's how you know
2026-05-26 02:56 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-26 02:56 UTC -
web:www.cvedetails.com
CVE -2025-55330 : Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
2026-05-26 02:56 UTC -
web:www.helpnetsecurity.com
Microsoft is working on a fix for CVE -2026-45585 (aka "Yellowkey"), a vulnerability that can be used to bypass Windows' BitLocker protection.
2026-05-26 02:56 UTC -
web:www.linkedin.com
Microsoft has released its May 2026 Patch Tuesday security updates, addressing more than 130 vulnerabilities across its software ecosystem, including Windows, Microsoft Office, SharePoint Server ...
2026-05-26 02:56 UTC -
web:www.tenable.com
Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code through profile fields and POST parameters. Attackers can inject script payloads in profile information fields like Address that execute when users visit the profile, or submit SQL injection payloads via the phone_no parameter to the user ...
2026-05-26 02:56 UTC -
web:www.thehackerwire.com
How do I fix or mitigate CVE-2018-25330 ? To protect against CVE-2018-25330 , you should: (1) Apply the latest security patches from the vendor, (2) Check official security advisories for specific remediation steps, (3) Update affected software to the latest version, and (4) Monitor your systems for any signs of exploitation.
2026-05-26 02:56 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's May 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-05-26 02:56 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.