CVE-2022-4050
JoomSport < 5.2.8 - Unauthenticated SQLi
Record summary
CVE-2022-4050 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 13, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 17, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
JoomSportDefault status: unaffected | CVE List | Before 5.2.8 | affected |
joomsportBrowse beardev / joomsport | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALWordPress JoomSport <5.2.8 - SQL InjectionCVSS 9.8
WordPress JoomSport plugin before 5.2.8 contains a SQL injection vulnerability. The plugin does not properly sanitize and escape a parameter before using it in a SQL statement. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations.
Impact
An attacker can execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
Remediation
Update to JoomSport plugin version 5.2.8 or later.
Source: ProjectDiscovery