Executive brief
EkRishta is a dating and relationship extension for the Joomla! content management system. The software contains security flaws that allow attackers to steal user data or take control of visitor browsers by injecting malicious code into profile pages. Additionally, attackers can manipulate the underlying database to access sensitive information by sending specially crafted web requests.
Technical details
The EkRishta extension for Joomla! (v2.10 and likely earlier) is vulnerable to both Persistent Cross-Site Scripting (XSS) and SQL Injection. The XSS vulnerability exists in profile information fields, such as the 'Address' field, where lack of input sanitization allows an attacker to store malicious JavaScript that executes in the context of any user viewing the profile. The SQL injection vulnerability resides in the 'user_setting' endpoint via the 'phone_no' POST parameter. An attacker can bypass existing filters to execute arbitrary SQL commands against the database. These vulnerabilities can be exploited remotely without authentication, potentially leading to full database compromise or session hijacking of other users.
Affected products
- Joomla! Extensions India EkRishta 2.10 and earlier
Timeline
- 2018-05-18: disclosed: Initial discovery and exploit publication by Sina Kheirkhah
- 2026-05-17: advisory: CVE record published and NVD entry created