Vulnerability CVE-2021-24575


Published: 2021-11-08

Description:
The School Management System ?????? WPSchoolPress WordPress plugin before 2.1.10 does not properly sanitize or use prepared statements before using POST variable in SQL queries, leading to SQL injection in multiple actions available to various authenticated users, from simple subscribers/students to teachers and above.

Type:

CWE-89

(Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.5/10
6.4/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Igexsolutions -> Wpschoolpress 

 References:
https://wpscan.com/vulnerability/83c9c3af-9eca-45e0-90d7-edc69e616e6a

Copyright 2024, cxsecurity.com

 

Back to Top