The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated users to retrieve information related to the courses, exams, departments as well as student's grades and PII such as email address, physical address, phone number etc
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-08-15T08:37:23

Updated: 2022-08-15T08:37:23

Reserved: 2022-07-11T00:00:00


Link: CVE-2022-2379

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-08-15T11:21:23.480

Modified: 2022-08-16T17:08:22.703


Link: CVE-2022-2379

JSON object: View

cve-icon Redhat Information

No data.

CWE