CVE-2022-4050

Published: Dic 19, 2022 Last Modified: Apr 17, 2025
ExploitDB:
Other exploit source:
Google Dorks:
CRITICAL 9,8
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high

Description

AI Translation Available

The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,7991
Percentile
1,0th
Updated

EPSS Score Trend (Last 90 Days)

Application

Joomsport by Beardev

Version Range Affected
To 5.2.8 (exclusive)
cpe:2.3:a:beardev:joomsport:*:*:*:*:*:wordpress:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://wpscan.com/vulnerability/5c96bb40-4c2d-4e91-8339-e0ddce25912f
https://wpscan.com/vulnerability/5c96bb40-4c2d-4e91-8339-e0ddce25912f