Products: 3
    Vulnerabilities: 5
    Known Exploited: 0
    0
    Critical Level Threats
    2
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2020-36154

    The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMDRIVE%\Pearson VUE" directory, which allows local users to obtain administrative privileges via a Trojan horse application.

    Last Modified: Nov 21, 2024
    Published: Jan 04, 2021

    CVE-2014-1454

    Pearson eSIS (Enterprise Student Information System) message board has stored XSS due to improper validation of user input

    Last Modified: Nov 21, 2024
    Published: Jan 08, 2020

    CVE-2015-0972

    Pearson ProctorCache before 2015.1.17 uses the same hardcoded password across different customers' installations, which allows remote attackers to modify test metadata or cause a denial of service (test disruption) by leveraging knowledge of this password.

    Last Modified: Apr 12, 2025
    Published: Jun 23, 2015

    CVE-2014-1455

    SQL injection vulnerability in the password reset functionality in Pearson eSIS Enterprise Student Information System, possibly 3.3.0.13 and earlier, allows remote attackers to execute arbitrary SQL commands via the new password.

    Last Modified: Apr 12, 2025
    Published: Apr 10, 2014

    CVE-2014-1942

    Cross-site scripting (XSS) vulnerability in aal/loginverification.aspx in Pearson eSIS Enterprise Student Information System allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Last Modified: Apr 12, 2025
    Published: Apr 02, 2014
    Items Per Page