Executive brief
Ek Rishta, a matrimonial and matchmaking extension for the Joomla! content management system, contains a security flaw that allows unauthorized individuals to access its database. By sending specially crafted web requests, an attacker can bypass security controls to view sensitive information stored in the system. This could lead to the exposure of private user data and potentially compromise the integrity of the website's records.
Technical details
An SQL injection vulnerability exists in the Ek Rishta component (version 2.10) for Joomla! within the 'user_detail' view. The root cause is improper neutralization of special elements used in an SQL command via the 'cid' GET parameter. An unauthenticated remote attacker can exploit this by sending a crafted GET request containing malicious SQL syntax. Successful exploitation allows the attacker to execute arbitrary SQL commands, potentially leading to the extraction of sensitive database information or unauthorized data modification. The extension has reportedly been unpublished from the Joomla! Extensions Directory.
Affected products
- Joomla! Extensions Ek Rishta 2.10
Timeline
- 2018-06-08: disclosed: Initial discovery and exploit development
- 2018-06-11: other: Exploit published on Exploit-DB
- 2026-05-23: advisory: CVE published/updated via VulnCheck and NVD