Record summary

CVE-2023-2636 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

The AN_GradeBook WordPress plugin through 5.0.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 30, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

AN_GradeBook

Default status: affected

CVE ListThrough 5.0.1affected

Proofs of concept

2

Catalogued exploits

ExploitDBWordPress Plugin AN_Gradebook 5.0.1 - SQLiExploitDB exploitby Lukas KinnebergNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHublukinneberg/CVE-2023-2636Repository PoCby lukinnebergStars: 1Not analyzed3 files

4.5 MiB

GitHub

PoC details

References

3