JoomSport
cpe:2.3:a:beardev:joomsport:*:*:*:*:wordpress:*:*
- <= 5.7.7
A time-based blind SQL injection vulnerability has been identified in the JoomSport WordPress plugin, specifically in versions through 5.7.7. The issue arises in the 'sortf' parameter, where insufficient escaping of user-supplied data allows unauthenticated attackers to inject additional SQL queries. This exploitation could lead to the extraction of sensitive information from the database.
Exploitation of this vulnerability allows for time-based blind SQL injection, where an attacker can manipulate SQL queries to extract data from the database.
The vulnerability can be reproduced by sending a request to a JoomSport player list endpoint with a crafted 'sortf' parameter. The injected SQL payload can be designed to extract data from the database, taking advantage of the application's SQL query handling.
Users are advised to update the JoomSport WordPress plugin to version 5.7.8 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.