WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是一个应用插件。 WordPress plugin Easy Student Results 2.2.8版本及之前版本存在跨站脚本漏洞,该漏洞源于在 REST API 中缺少授权。攻击者利用该漏洞获取敏感信息。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| Unknown | Easy Student Results | 2.2.8 ~ 2.2.8 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | WordPress Easy Student Results plugin through 2.2.8 is susceptible to information disclosure. The plugin lacks authorization in its REST API, which can allow an attacker to retrieve sensitive information related to courses, exams, and departments, as well as student grades and information such as email address, physical address, and phone number. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-2379.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2022-2116 | WordPress plugin Contact Form DB 跨站脚本漏洞 | |
| CVE-2022-2152 | WordPress plugin Duplicate Page and Post 跨站脚本漏洞 | |
| CVE-2022-2180 | WordPress theme GREYD.SUITE 代码问题漏洞 | |
| CVE-2022-2314 | WordPress plugin VR Calendar 操作系统命令注入漏洞 | |
| CVE-2022-2354 | WordPress plugin WP-DBManager 代码注入漏洞 | |
| CVE-2022-2378 | WordPress plugin Easy Student Results 跨站脚本漏洞 | |
| CVE-2022-2381 | WordPress plugin E Unlocked - Student Result 跨站请求伪造漏洞 | |
| CVE-2022-2384 | WordPress plugin Digital Publications by Supsystic 跨站脚本漏洞 | |
| CVE-2022-2535 | WordPress plugin SearchWP Live Ajax Search 安全漏洞 |
暂无评论