A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the category management area in backend.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 04 Jun 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Hikashop
Hikashop hikashop
CPEs cpe:2.3:a:hikashop:hikashop:*:*:*:*:*:joomla\!:*:*
Vendors & Products Hikashop
Hikashop hikashop

Thu, 03 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Feb 2025 22:00:00 +0000

Type Values Removed Values Added
References

Tue, 25 Feb 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Feb 2025 05:30:00 +0000

Type Values Removed Values Added
Description A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the category management area in backend.
Title Extension - hikashop.com - SQL injection in Hikashop component version 3.3.0 - 5.1.4 for Joomla
Weaknesses CWE-89
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2025-04-04T04:35:49.991Z

Reserved: 2025-01-01T04:33:02.765Z

Link: CVE-2025-22210

cve-icon Vulnrichment

Updated: 2025-02-25T14:34:49.715Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-25T06:15:23.343

Modified: 2025-06-04T20:51:12.953

Link: CVE-2025-22210

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.