CVE-2022-2312

Student Result or Employee Database <= 1.7.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting

mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
6.1
CVSS Score
6.1
CVSS Score
medium
Severity
1.7.5
Patched in
540d
Time to patch

Description

The Student Result or Employee Database plugin for WordPress is vulnerable to Cross-Site Request Forgery on its ajax actions in versions up to, and including, 1.7.4 due to improper or missing nonce verification. This allows unauthenticated attackers to utilize these ajax actions to add or delete students/employees provided they can trick a contributor or higher-privileged user into clicking on a link. Furthermore, due to insufficient input sanitization of user input, this weakness can be utilized for Stored Cross-Site Scripting.

CVSS Vector Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Low
Confidentiality
Low
Integrity
None
Availability

Technical Details

Affected versions<=1.7.4
PublishedAugust 1, 2022
Last updatedJanuary 22, 2024
Affected pluginsimple-student-result

Check if your site is affected.

Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.