CVE-2022-2379: WordPress Easy Student Results <=2.2.8 - Improper Authorization

CVE-2022-2379: WordPress Easy Student Results <=2.2.8 - Improper Authorization-渗透云记 - 专注于网络安全与技术分享
CVE-2022-2379: WordPress Easy Student Results <=2.2.8 - Improper Authorization
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2022-2379: WordPress EASy Student Results <=2.2.8 – Improper Authorization

漏洞描述

WordPress Easy Student Results plugin through 2.2.8 is susceptible to information disclosure. The plugin lacks authorization in its REST API, which can allow an attacker to retrieve sensitive information related to courses, exams, and departments, as well as student grades and information such as email address, physical address, and phone number.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享