PT-2026-68058 · Joomla · Joomsport

·

CVE-2026-11920

·

Published

2026-08-05

·

Updated

2026-08-05

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions JoomSport – for Sports: Team & League, Football, Hockey & more versions prior to 5.7.10
Description This issue is a time-based SQL Injection, a technique used to infer data from a database by observing the time it takes for the server to respond to specific queries. The flaw exists due to insufficient escaping of user-supplied parameters and a lack of proper preparation of the SQL query. Authenticated attackers with administrator-level access can append additional SQL queries to extract sensitive information from the database. Because the affected admin page lacks nonce or CSRF (Cross-Site Request Forgery) protection on GET requests, unauthenticated attackers may exploit this by tricking an administrator into issuing a crafted request. The issue is triggered when the order parameter is manipulated while the orderby parameter is also present and non-empty.
Recommendations Update to a version newer than 5.7.9. Avoid using the order parameter in the affected admin page until the update is applied.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11920

Affected Products

Joomsport