The School Management Pro <= 9.9.6 - Remote Code Execution

2022-06-27 00:00
Anonymous

Strategic Overview

Status
Patched in 9.9.7
Affected Version<= 9.9.6
CVSS9.8Critical
CVECVE-2022-1609
View all The School Management Pro vulnerabilities

Vulnerability Overview

The plugin School Management Pro in version 8.9 contains code that allows an attacker to remotely execute code.

Technical Analysis

REMEDIATION: Update to version 9.9.7, or a newer patched version --- IDENTIFIER: CWE-912 (Hidden Functionality) The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product's users or administrators.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C