PT-2014-4191 · Pearson · Pearson Esis Enterprise Student Information System

Published

2014-04-10

·

Updated

2018-10-09

·

CVE-2014-1455

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Pearson eSIS Enterprise Student Information System versions prior to 3.3.0.14
Description The issue concerns a SQL injection vulnerability in the password reset functionality. This allows remote attackers to execute arbitrary SQL commands via the new password.
Recommendations For versions prior to 3.3.0.14, update to version 3.3.0.14 or later to resolve the issue.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-1455

Affected Products

Pearson Esis Enterprise Student Information System