pearson records
5 published records for vendor pearson.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-255 Credentials Management Errors1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2020-36154No exploit | The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMDRIVE%\Pearson VUE" dpearson · vue testing system · CWE-732 | High7.8 | — | 0.4% | Jan 4, 2021 |
30Monitor | CVE-2014-1455No exploit | SQL injection vulnerability in the password reset functionality in Pearson eSIS Enterprise Student Information System, possibly 3.3.0.13 andpearson · esis enterprise student information system · CWE-89 | High7.5 | — | 1.3% | Apr 10, 2014 |
20Monitor | CVE-2015-0972No exploit | Pearson ProctorCache before 2015.1.17 uses the same hardcoded password across different customers' installations, which allows remote attackpearson · proctorcache · CWE-255 | Medium5.0 | — | 1.4% | Jun 23, 2015 |
19Monitor | CVE-2014-1454No exploit | Pearson eSIS (Enterprise Student Information System) message board has stored XSS due to improper validation of user inputpearson · esis enterprise student information system · CWE-79 | Medium4.8 | — | 0.6% | Jan 8, 2020 |
17Monitor | CVE-2014-1942No exploit | Cross-site scripting (XSS) vulnerability in aal/loginverification.aspx in Pearson eSIS Enterprise Student Information System allows remote apearson · esis enterprise student information system · CWE-79 | Medium4.3 | — | 1.0% | Apr 1, 2014 |
- CVE-2020-3615431Monitor
The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMDRIVE%\Pearson VUE" d
HighCVSS 7.8No exploitEPSS 0%pearson · vue testing systemJan 4, 2021
- CVE-2014-145530Monitor
SQL injection vulnerability in the password reset functionality in Pearson eSIS Enterprise Student Information System, possibly 3.3.0.13 and
HighCVSS 7.5No exploitEPSS 1%pearson · esis enterprise student information systemApr 10, 2014
- CVE-2015-097220Monitor
Pearson ProctorCache before 2015.1.17 uses the same hardcoded password across different customers' installations, which allows remote attack
MediumCVSS 5.0No exploitEPSS 1%pearson · proctorcacheJun 23, 2015
- CVE-2014-145419Monitor
Pearson eSIS (Enterprise Student Information System) message board has stored XSS due to improper validation of user input
MediumCVSS 4.8No exploitEPSS 1%pearson · esis enterprise student information systemJan 8, 2020
- CVE-2014-194217Monitor
Cross-site scripting (XSS) vulnerability in aal/loginverification.aspx in Pearson eSIS Enterprise Student Information System allows remote a
MediumCVSS 4.3No exploitEPSS 1%pearson · esis enterprise student information systemApr 1, 2014