LeagueManager <= 3.9.11 - SQL Injection
The plugin does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action (available to unauthenticated users), leading to an SQL injection.
leaguemanagerPoC 已收录
CVSS—
共找到 1 条公开漏洞记录
The plugin does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action (available to unauthenticated users), leading to an SQL injection.