Description
Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an open redirect.
Published: 2026-07-20
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The updated description now indicates an open-redirect flaw in the Hikashop extension for Joomla. The exact details of the flaw are not provided in the new data, but it continues to be a CWE‑601 type vulnerability that can allow attackers to redirect users to arbitrary external sites, potentially enabling phishing or malicious content delivery.

Affected Systems

The flaw affects all installations of the Hikashop extension for Joomla with a version number less than 6.5.2. No specific sub‑version details are documented, so any version that predates 6.5.2 is potentially vulnerable.

Risk and Exploitability

The attacker can exploit the vulnerability by crafting a URL that includes a redirect parameter pointing to a malicious destination. The CVSS score of 6.1 reflects moderate severity, while the EPSS score of <1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, so it is not known to be actively exploited. The primary risk is the facilitation of phishing attacks that could lead to credential theft or malicious site visits, rather than direct compromise of the system.

Generated by OpenCVE AI on August 3, 2026 at 01:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Hikashop to version 6.5.2 or later
  • If an upgrade is not feasible, implement server‑side validation of redirect destinations to limit them to approved domains
  • Configure Joomla to strip or reject any redirect parameters that are not explicitly permitted by the application logic

Generated by OpenCVE AI on August 3, 2026 at 01:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.hikashop.com/ cve-icon
History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Hikashop.com
Hikashop.com hikashop Extension For Joomla
Vendors & Products Hikashop.com
Hikashop.com hikashop Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Hikashop is vulnerable to an open redirect. Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an open redirect.

Tue, 21 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Description The Joomla extension Hikashop is vulnerable to an open redirect.
Title Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2
Weaknesses CWE-601
References

Subscriptions

Hikashop.com Hikashop Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T14:56:45.755Z

Reserved: 2026-07-12T05:35:55.729Z

Link: CVE-2026-61901

cve-icon Vulnrichment

Updated: 2026-07-21T19:12:02.960Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T01:15:03Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')