Beveiligingsadvies

CVE-2023-4776

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-10-16 19:38:59
Laatst bijgewerkt 2025-04-23 16:13:48
Toegewezen door WPScan
CVSS-score 8.8
Status PUBLISHED

Beschrijving

The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query, leading to a SQL injection exploitable by relatively low-privilege users like Teachers.