What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Felix Welberg SIS Handball allows SQL Injection.This issue affects SIS Handball: from n/a through 1.0.45.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Felix Welberg SIS Handball allows SQL Injection.This issue affects SIS Handball: from n/a through 1.0.45.
Explanation of Vulnerability in Simple Terms
SIS Handball versions up to 1.0.45 contain a SQL injection vulnerability in a high-privilege function. An authenticated administrator can craft malicious input to read or modify database contents. The vulnerability affects confidentiality and availability but requires admin-level access to exploit.
What an attacker can do
Read or modify database records if authenticated as an administrator.
Potential impact on your site
An admin account compromise could expose or alter handball league data and user information stored in the database.
Conditions required to exploit
Attacker must have administrator-level access to the application.
Key dates
External resources
Related vulnerabilities