CVE-2022-2379
Easy Student Results <= 2.2.8 - Sensitive Information Disclosure via REST API
Record summary
CVE-2022-2379 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated users to retrieve information related to the courses, exams, departments as well as student's grades and PII such as email address, physical address, phone number etc
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Easy Student Results | CVE List | 2.2.8 to ≤ 2.2.8 | affected |
Nuclei templates
1ProjectDiscoveryHIGHWordPress Easy Student Results <=2.2.8 - Improper AuthorizationCVSS 7.5
WordPress Easy Student Results plugin through 2.2.8 is susceptible to information disclosure. The plugin lacks authorization in its REST API, which can allow an attacker to retrieve sensitive information related to courses, exams, and departments, as well as student grades and information such as email address, physical address, and phone number.
Impact
An attacker can gain access to sensitive student information, potentially compromising their privacy and security.
Remediation
Update to the latest version of the WordPress Easy Student Results plugin (2.2.8) to fix the improper authorization vulnerability.
Source: ProjectDiscovery