The School Management System... CVE-2023-4776

- AV AC AU C I A
发布: 2023-10-16
修订: 2023-11-07

The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query, leading to a SQL injection exploitable by relatively low-privilege users like Teachers.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息