7.5

CVE-2022-2379

Exploit

Easy Student Results <= 2.2.8 - Sensitive Information Disclosure via REST API

Easy Student Results <= 2.2.8 - Missing Authorization to Sensitive Information Disclosure

The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated users to retrieve information related to the courses, exams, departments as well as student's grades and PII such as email address, physical address, phone number etc
Mögliche Gegenmaßnahme
Easy Student Results: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Easy Student Results ProjectEasy Student Results SwPlatformwordpress Version <= 2.2.8
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Easy Student Results
Version *-2.2.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.8% 0.846
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://wpscan.com/vulnerability/0773ba24-212e-41d5-9ae0-1416ea2c9db6
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/d1efe450-d081-421e-95c3-f2d79c328a33
Third Party Advisory