PT-2022-18265 · WordPress · Joomsport

Salim Al-Wahaibi

·

Published

2022-09-06

·

Updated

2024-01-11

·

CVE-2022-2717

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress versions up to, and including, 5.2.5
Description The issue is related to SQL Injection via the orderby parameter on the "joomsport-events-form" page. This vulnerability is caused by insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. As a result, authenticated attackers with administrative privileges can append additional SQL queries into already existing queries, which can be used to extract sensitive information from the database.
Recommendations For versions up to, and including, 5.2.5, consider disabling the orderby parameter on the "joomsport-events-form" page as a temporary workaround until a patch is available. Restrict access to the "joomsport-events-form" page to minimize the risk of exploitation. Avoid using the orderby parameter in the affected page until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-2717

Affected Products

Joomsport