S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-2379 Scanner

CVE-2022-2379 scanner - Sensitive Information Disclosure vulnerability in Easy Student Results

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.2k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-2379
7.5
CVSS

The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated users to retrieve information related to the courses, exams, departments as well as student's grades and PII such as email address, physical address, phone number etc

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Easy Student Results
2.2.8
Updated Aug 22, 2026View on NVD →
Detail

Easy Student Results is a WordPress plugin that is widely used by schools and universities to manage student grades, exams, courses, and departments. This plugin offers an easy-to-use interface for teachers and students to efficiently monitor academic performance. Its aim is to streamline the academic process and make it more convenient for both the administration and the students. Easy Student Results is considered an efficient tool in managing all academic activities and its simplicity in architecture make it easy to use for everyone.

One of the most recent vulnerabilities detected in Easy Student Results is CVE-2022-2379. This vulnerability allows attackers to retrieve confidential and sensitive information related to the courses, exams, departments, and student's grades. Unauthenticated users can easily exploit the vulnerability as it lacks authorisation in its REST API. This means that accessing information on the platform is incredibly easy for anyone with malicious intent, making it a high-risk vulnerability.

When exploited, this vulnerability can lead to serious consequences such as the theft of students' personal information, such as their email address, physical address, and phone number. This can, in turn, lead to other cyber attacks such as identity theft, phishing, and other malicious activities. Furthermore, the attacker can sabotage the academic process by tampering with grades, changing courses and exams, or even deleting important data. This vulnerability, if unchecked, can lead to loss of reputation, lawsuits, and financial loss for the institution that is using Easy Student Results.

In conclusion, security is of vital importance while using digital assets. Those who use Easy Student Results must be aware of the potential risks and take necessary precautions to protect their data. With the help of s4e.io, it is easy to identify vulnerabilities and prevent attacks that can harm digital assets. Thanks to its pro features, users can quickly learn about vulnerabilities and keep their data secure.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Use proper authentication methods such as strong passwords, two-factor authentication, and single sign-on.
  • Regularly update the software and apply the latest security patches.
  • Implement access control mechanisms to restrict access to sensitive data.
  • Monitor the REST API activity and detect any suspicious requests.
  • Educate users about the risks of this vulnerability and how to prevent it.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.