CVE-2021-24384
JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.1.7 - Object Injection
criticalDeserialization of Untrusted Data
9.8
CVSS Score
9.8
CVSS Score
critical
Severity
5.1.8
Patched in
959d
Time to patch
Description
The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter, leading to a PHP Object Injection issue. Even though the plugin does not have a suitable gadget chain to exploit this, other installed plugins could, which might lead to more severe issues such as RCE
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAttack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
High
Confidentiality
High
Integrity
High
Availability
Technical Details
Affected versions
<5.1.8PublishedJune 8, 2021
Last updatedJanuary 22, 2024
Affected pluginjoomsport-sports-league-results-management
Check if your site is affected.
Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.