CVE-2022-1609
The School Management < 9.9.7 - Unauthenticated RCE via REST api
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
4
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an unauthenticated attacker to execute arbitrary PHP code on the site.
El complemento de WordPress School Management anterior a 9.9.7 contiene una puerta trasera ofuscada inyectada en su código de verificación de licencia que registra un controlador de API REST, lo que permite a un atacante no autenticado ejecutar código PHP arbitrario en el sitio.
The plugin School Management Pro in version 8.9 contains code that allows an attacker to remotely execute code.
*Credits:
Jetpack Scan Team + WordPress elevated support team, WPScan
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-05-06 CVE Reserved
- 2022-05-27 First Exploit
- 2022-06-27 CVE Published
- 2024-08-03 CVE Updated
- 2024-11-11 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
- CWE-912: Hidden Functionality
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/0xSojalSec/-CVE-2022-1609 | 2022-06-09 | |
https://github.com/0xSojalSec/CVE-2022-1609 | 2022-06-09 | |
https://github.com/savior-only/CVE-2022-1609 | 2022-05-27 | |
https://wpscan.com/vulnerability/e2d546c9-85b6-47a4-b951-781b9ae5d0f2 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Weblizar Search vendor "Weblizar" | School Management Search vendor "Weblizar" for product "School Management" | < 9.9.7 Search vendor "Weblizar" for product "School Management" and version " < 9.9.7" | pro, wordpress |
Affected
|