Student Result or Employee Database <= 1.6.3 - Authentication Bypass
2017-09-21 00:00
Benjamin LimStrategic Overview
StatusPatched in 1.6.4
Affected PluginStudent Result or Employee Database
Affected Version
<= 1.6.3CVSS9.8Critical
CVE
CVE-2017-14766Vulnerability Overview
The Simple Student Result plugin before 1.6.4 for WordPress has an Authentication Bypass vulnerability because the fn_ssr_add_st_submit() function and fn_ssr_del_st_submit() function in functions.php only require knowing the student id number.
Technical Analysis
REMEDIATION: Update to version 1.6.4, or a newer patched version --- IDENTIFIER: CWE-288 (Authentication Bypass Using an Alternate Path or Channel) The product requires authentication, but the product has an alternate path or channel that does not require authentication.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C