SQL Injection Vulnerability in LeagueManager Plugin for WordPress
CVE-2013-1852
Currently unrated
What is CVE-2013-1852?
The LeagueManager plugin for WordPress is susceptible to an SQL injection flaw that can be exploited by remote attackers. Specifically, the vulnerability arises in the leaguemanager.php file, allowing attackers to manipulate SQL queries through the 'league_id' parameter on the leaguemanager-export page. If successfully exploited, this can result in the execution of arbitrary SQL commands, potentially leading to unauthorized access to sensitive database information. It is critical for users of LeagueManager to update to version 3.8.1 or later to mitigate this security risk.