Description
In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view.
Remediation
References
Related Vulnerabilities
Liferay Portal Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-10795)
WordPress Plugin AppPresser-Mobile App Framework Security Bypass (4.3.0)
WordPress Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability (CVE-2022-3590)
WordPress Plugin Live Scores for SportsPress Multiple Vulnerabilities (1.9.0)