Student Result or Employee Database <= 1.6.3 - Authentication Bypass

2017-09-21 00:00
Benjamin Lim

Strategic Overview

Status
Patched in 1.6.4
Affected Version<= 1.6.3
CVSS9.8Critical
CVECVE-2017-14766
View all Student Result or Employee Database vulnerabilities

Vulnerability Overview

The Simple Student Result plugin before 1.6.4 for WordPress has an Authentication Bypass vulnerability because the fn_ssr_add_st_submit() function and fn_ssr_del_st_submit() function in functions.php only require knowing the student id number.

Technical Analysis

REMEDIATION: Update to version 1.6.4, or a newer patched version --- IDENTIFIER: CWE-288 (Authentication Bypass Using an Alternate Path or Channel) The product requires authentication, but the product has an alternate path or channel that does not require authentication.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C