The School Management System – WPSchoolPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.10. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authenticated attackers, with teacher-level access and above, to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.
Metrics
Affected Vendors & Products
References
History
Mon, 28 Oct 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Jdsofttech
Jdsofttech school Management System |
|
CPEs | cpe:2.3:a:jdsofttech:school_management_system:*:*:*:*:*:*:*:* | |
Vendors & Products |
Jdsofttech
Jdsofttech school Management System |
|
Metrics |
ssvc
|
Sat, 26 Oct 2024 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The School Management System – WPSchoolPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.10. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authenticated attackers, with teacher-level access and above, to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account. | |
Title | School Management System – WPSchoolPress <= 2.2.10 - Insecure Direct Object Reference to Authenticated (Teacher+) Account Takeover/Privilege Escalation | |
Weaknesses | CWE-639 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-26T08:36:00.481Z
Updated: 2024-10-28T19:23:08.421Z
Reserved: 2024-10-08T16:50:22.333Z
Link: CVE-2024-9637
Vulnrichment
Updated: 2024-10-28T19:23:01.453Z
NVD
Status : Awaiting Analysis
Published: 2024-10-26T09:15:04.900
Modified: 2024-10-28T13:58:09.230
Link: CVE-2024-9637
Redhat
No data.