CVE-2024-9637
EUVD-2024-5007026.10.2024, 09:15
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.10. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authenticated attackers, with teacher-level access and above, to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| jdsofttech | school_management_system | 𝑥 ≤ 2.2.10 |
| igexsolutions | wpschoolpress | 𝑥 < 2.2.11 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration