plugin

Sis Handball Vulnerabilities

2 known security issues reported for the Sis Handball WordPress plugin. Most recent disclosed Sep 4, 2023.

1 high 1 medium

Running Sis Handball on your site? Check whether your installed version is affected.

Scan your site free

SIS Handball <= 1.0.45 - Cross-Site Request Forgery

medium

The SIS Handball plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.45. This is due to missing nonce validation on the page_options() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can t...

CVSS:
4.3
Affected:
up to 1.0.45
Fix:
No patched version reported
Disclosed:
Sep 4, 2023

CVE-2023-41684 on NVD →

SIS Handball <= 1.0.45 - Authenticated (Administrator+) SQL Injection via 'orderby'

high

The SIS Handball plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in versions up to, and including, 1.0.45 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attacke...

CVSS:
7.2
Affected:
up to 1.0.45
Fix:
No patched version reported
Disclosed:
May 23, 2023

CVE-2023-33924 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database