vendor:
JoomSport
by:
Pablo Santiago
9.8
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: JoomSport
Affected Version From: 3.3
Affected Version To: 3.3
Patch Exists: YES
Related CWE: CVE-2019-14348
CPE: a:beardev:joomsport:3.3
Metasploit:
https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2018-14348/, https://www.rapid7.com/db/vulnerabilities/amazon-linux-ami-2-cve-2018-14348/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2018-14348/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2018-14348/
Other Scripts:
N/A
Platforms Tested: Windows and Kali linux
2019
JoomSport 3.3 – for Sports – SQL injection
Through the SQL injection vulnerability, a malicious user could inject SQL code in order to steal information from the database, modify data from the database, even delete database or data from them.
Mitigation:
Input validation and sanitization should be done to prevent SQL injection attacks.