vendor:
EkRishta
by:
L0RD
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: EkRishta
Affected Version From: 2.1
Affected Version To: 2.1
Patch Exists: NO
Related CWE:
CPE: a:joomla:ek_rishta:2.10
Platforms Tested: Windows 10
2018
Joomla! Component EkRishta 2.10 – ‘username’ SQL Injection
The Joomla! Component EkRishta 2.10 is vulnerable to a SQL Injection attack. The 'username' parameter is not properly sanitized, allowing an attacker to inject SQL code into the query. This can lead to unauthorized access, data manipulation, or other malicious activities.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user input and use prepared statements or parameterized queries to prevent SQL Injection attacks. The vendor should release a patch or update to fix this vulnerability.