CVE-2018-12254
HIGHHarmis Ek Rishta <2.10 - SQL Injection
Title source: llmDescription
router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla! allows SQL Injection via the PATH_INFO to a home/requested_user/Sent%20interest/ URI.
Exploits (1)
exploitdb
WORKING POC
by Guilherme Assmann · phpwebappsphp
https://www.exploit-db.com/exploits/44893
Scores
CVSS v3
8.8
EPSS
0.0037
EPSS Percentile
58.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
harmistechnology/ek_rishta
2.10
Published
Jun 12, 2018
Tracked Since
Feb 18, 2026