Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-4776

Опубликовано: 16 окт. 2023
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query, leading to a SQL injection exploitable by relatively low-privilege users like Teachers.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:igexsolutions:wpschoolpress:*:*:*:*:*:wordpress:*:*
Версия до 2.2.5 (исключая)

EPSS

Процентиль: 53%
0.003
Низкий

8.8 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.8
github
больше 2 лет назад

The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query, leading to a SQL injection exploitable by relatively low-privilege users like Teachers.

EPSS

Процентиль: 53%
0.003
Низкий

8.8 High

CVSS3

Дефекты

CWE-89