SQL Injection Vulnerability in LeagueManager Plugin for WordPress
CVE-2013-1852

Currently unrated

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
5 February 2014

What is CVE-2013-1852?

The LeagueManager plugin for WordPress is susceptible to an SQL injection flaw that can be exploited by remote attackers. Specifically, the vulnerability arises in the leaguemanager.php file, allowing attackers to manipulate SQL queries through the 'league_id' parameter on the leaguemanager-export page. If successfully exploited, this can result in the execution of arbitrary SQL commands, potentially leading to unauthorized access to sensitive database information. It is critical for users of LeagueManager to update to version 3.8.1 or later to mitigate this security risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.