Sploitus

CVE-2023-4776

1 known exploit for CVE-2023-4776

The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query, leading to a SQL injection exploitable by relatively low-privilege users like Teachers.

Affected products
School Management System
Igexsolutions Wpschoolpress
< 2.2.5
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
0.7% (52th percentile)
Weakness
CWE-89
NVD status
Modified
Published
2023-10-16
CVE-2023-4776 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2023-4776

Proof-of-concept code and exploit modules indexed by Sploitus