Security readout for executives and security teams
Plain-English summary
CVE-2022-23797 affects Joomla! CMS versions 3.0.0 through 3.10.6 and 4.0.0 through 4.1.0. The issue is inadequate filtering of selected IDs in a request, creating possible SQL injection risk. The source bundle does not provide CVSS, impact depth, or confirmed exploitation.
Executive priority
Treat this as a high-priority CMS maintenance issue for exposed Joomla! sites because SQL injection can affect sensitive data. Urgency is lower than a confirmed exploited KEV item, but affected public sites should be upgraded promptly.
Technical view
The CVE describes insufficient filtering of selected ID values in Joomla! Core request handling, potentially allowing SQL injection. Affected ranges are Joomla! CMS 3.0.0-3.10.6 and 4.0.0-4.1.0. No CWE, CVSS vector, exploit detail, or fixed version is provided in the supplied bundle.
Likely exposure
Exposure is most likely for internet-facing Joomla! sites running the affected 3.x or 4.x ranges. Sites no longer on those versions may still need verification because the bundle does not name fixed releases.
Exploitation context
The supplied sources do not show active exploitation, and CISA KEV is false. Public vulnerability records identify possible SQL injection, but provide no exploit status, required privileges, or affected endpoint details in the bundle.
Researcher notes
Evidence is limited to the CVE description and Joomla! advisory reference. Do not assume exploitability conditions, authentication requirements, or fixed versions without reading the vendor advisory. Validation should focus on version exposure and vendor-confirmed remediation status.
Mitigation direction
- Inventory Joomla! CMS versions across all public and internal sites.
- Check Joomla! vendor advisory for the fixed release path before upgrading.
- Prioritize upgrades for internet-facing affected Joomla! instances.
- Review web application firewall and database monitoring alerts for suspicious request patterns.
Validation and detection
- Confirm each Joomla! site version against the affected ranges.
- Verify remediation against Joomla! Project guidance, not assumptions.
- Review logs for unusual requests involving selected ID parameters.
- Confirm no unsupported Joomla! installations remain exposed.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
Database behavior lookup
The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2022-23797 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://developer.joomla.org/security-centre/874-20220305-core-inadequate-filtering-on-the-selected-ids.htmlCVE reference · x_refsource_MISC, vendor-advisory
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
