A vulnerability has been found in Joomlaextensions EkRishta 2.10 on Joomla and classified as critical . This issue affects the function user_setting of the component Setting Handler . This manipulation of the argument phone_no causes sql injection. This vulnerability appears as CVE-2018-25330 . The attack may be initiated remotely. In addition, an exploit is available.