Beta

Report

Student Result or Employee Database <= 1.7.4 is vulnerable to Stored Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability

Unauthenticated
Published
2022-07-31

The Student Result or Employee Database plugin for WordPress is vulnerable to Cross-Site Request Forgery on its ajax actions in versions up to, and including, 1.7.4 due to improper or missing nonce verification. This allows unauthenticated attackers to utilize these ajax actions to add or delete students/employees provided they can trick a contributor or higher-privileged user into clicking on a link. Furthermore, due to insufficient input sanitization of user input, this weakness can be utilized for Stored Cross-Site Scripting.

CVSS

Score:6.1

Severity:Medium

Version: 1.7.4

There is a patch available in v1.7.5 and we strongly recommend you update to this version as soon as possible.