Vulnerability Description
The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Beardev | Joomsport | 3.3 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/153963/WordPress-JoomSport-3.3-SQL-InjectioExploitThird Party AdvisoryVDB Entry
- https://hackpuntes.com/cve-2019-14348-joomsport-for-sports-sql-injection/Third Party Advisory
- https://wpvulndb.com/vulnerabilities/9499Third Party Advisory
- http://packetstormsecurity.com/files/153963/WordPress-JoomSport-3.3-SQL-InjectioExploitThird Party AdvisoryVDB Entry
- https://hackpuntes.com/cve-2019-14348-joomsport-for-sports-sql-injection/Third Party Advisory
- https://wpvulndb.com/vulnerabilities/9499Third Party Advisory
FAQ
What is CVE-2019-14348?
CVE-2019-14348 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter.
How severe is CVE-2019-14348?
CVE-2019-14348 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-14348?
Check the references section above for vendor advisories and patch information. Affected products include: Beardev Joomsport.