Record summary

CVE-2022-4050 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 13, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 17, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

JoomSport

Default status: unaffected

CVE ListBefore 5.2.8affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress JoomSport <5.2.8 - SQL InjectionCVSS 9.8

WordPress JoomSport plugin before 5.2.8 contains a SQL injection vulnerability. The plugin does not properly sanitize and escape a parameter before using it in a SQL statement. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations.

Impact

An attacker can execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.

Remediation

Update to JoomSport plugin version 5.2.8 or later.

WeaknessesCWE-89
Authorstheamanrawat
Template tagstime-based-sqlicvecve2022wpscanwp-pluginwpjoomsport-sports-league-results-managementwordpresssqliunauthbeardevvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:beardev:joomsport:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2