Description
The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query, leading to a SQL injection exploitable by relatively low-privilege users like Teachers.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54622 | The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query, leading to a SQL injection exploitable by relatively low-privilege users like Teachers. |
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-04-23T16:13:48.916Z
Reserved: 2023-09-05T15:05:25.688Z
Link: CVE-2023-4776
No data.
Status : Modified
Published: 2023-10-16T20:15:16.250
Modified: 2025-04-23T17:16:46.423
Link: CVE-2023-4776
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD