PT-2023-30593 · WordPress · School Management System

Dao Xuan Hieu

·

Published

2023-10-16

·

Updated

2023-10-19

·

CVE-2023-4776

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions School Management System WordPress plugin versions prior to 2.2.5
Description The issue is related to a SQL injection that can be exploited by relatively low-privilege users, such as Teachers. This occurs because the WordPress esc sql() function is used on a field not delimited by quotes and the query is not first prepared.
Recommendations For versions prior to 2.2.5, update to version 2.2.5 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive database queries to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-4776

Affected Products

School Management System