CVE-2013-1852

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
05/02/2014
Last modified:
11/04/2025

Description

SQL injection vulnerability in leaguemanager.php in the LeagueManager plugin before 3.8.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the league_id parameter in the leaguemanager-export page to wp-admin/admin.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kolja_schleich:leaguemanager:*:*:*:*:*:wordpress:*:* 3.8 (including)
cpe:2.3:a:kolja_schleich:leaguemanager:1.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:kolja_schleich:leaguemanager:1.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:kolja_schleich:leaguemanager:1.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:kolja_schleich:leaguemanager:1.2.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:kolja_schleich:leaguemanager:1.2.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:kolja_schleich:leaguemanager:1.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:kolja_schleich:leaguemanager:1.4:*:*:*:*:wordpress:*:*
cpe:2.3:a:kolja_schleich:leaguemanager:1.4.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:kolja_schleich:leaguemanager:1.4.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:kolja_schleich:leaguemanager:1.5:*:*:*:*:wordpress:*:*
cpe:2.3:a:kolja_schleich:leaguemanager:2.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:kolja_schleich:leaguemanager:2.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:kolja_schleich:leaguemanager:2.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:kolja_schleich:leaguemanager:2.3:*:*:*:*:wordpress:*:*