Search Results (24 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-9919 1 Harmistechnology 1 Je Messenger 2024-11-21 5.4 Medium
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to craft messages in a way that JavaScript gets executed on the side of the receiving user when the message is opened, aka XSS.
CVE-2019-9918 1 Harmistechnology 1 Je Messenger 2024-11-21 9.1 Critical
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Input does not get validated and queries are not written in a way to prevent SQL injection. Therefore arbitrary SQL-Statements can be executed in the database.
CVE-2018-7315 1 Harmistechnology 1 Ek Rishta 2024-11-21 N/A
SQL Injection exists in the Ek Rishta 2.9 component for Joomla! via the gender, age1, age2, religion, mothertounge, caste, or country parameter.
CVE-2018-12254 1 Harmistechnology 1 Ek Rishta 2024-11-21 N/A
router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla! allows SQL Injection via the PATH_INFO to a home/requested_user/Sent%20interest/ URI.