CVE-2025-25225
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-25225 is a privilege escalation vulnerability that affects the Hikashop component versions 1.0.0-5.1.3 used in Joomla. Authenticated attackers, such as administrators, can exploit this vulnerability to elevate their privileges and gain Super Admin Permissions. Successful exploitation allows attackers to have full control over the vulnerable Joomla installation, which poses a significant risk to the security of the website and its data. It is essential for Joomla users to update their Hikashop component to a patched version to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.