CVE-2025-22210
CVSS 3.1 Score 7.2 of 10 (high)
Details
Published Feb 25, 2025
CWE ID 89
Summary
CVE-2025-22210 is a SQL injection vulnerability affecting the Hikashop component versions 3.3.0-5.1.4 used in Joomla. This issue grants authenticated attackers, specifically administrators, the ability to execute arbitrary SQL commands within the category management area of the backend. Successful exploitation could result in unauthorized data access or manipulation, leading to potential security risks and potential damage to the affected system. It is advised that users upgrade to the latest version of Hikashop to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share