vendor:
Unknown
by:
Guilherme Assmann
8.8
CVSS
HIGH
SQL Injection
Unknown
CWE
Product Name: Unknown
Affected Version From: 2.1
Affected Version To: 2.1
Patch Exists: Unknown
Related CWE: CVE-2018-12254
CPE: Unknown
Platforms Tested: MacOSX, Safari, Chrome
2018
SQL Injection Joomla Component Ek rishta 2.10 – SQL Injection
To exploit this vulnerability, the user must be logged on to the platform! The vulnerability allows SQL Injection via the PATH_INFO to a home/requested_user/Sent%20interest/[username] URI.
Mitigation:
Unknown