Lucene search

K
cvePatchstackCVE-2024-27966
HistoryApr 11, 2024 - 1:25 a.m.

CVE-2024-27966

2024-04-1101:25:06
CWE-79
Patchstack
web.nvd.nist.gov
39
cve-2024-27966
organization
individual
nvd
security problem

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

AI Score

9.1

Confidence

High

EPSS

0

Percentile

9.0%

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in ExpressTech Quiz And Survey Master allows Stored XSS.This issue affects Quiz And Survey Master: from n/a through 8.2.2.

Affected configurations

Vulners
Node
expresstechquiz_and_survey_masterRange8.2.2wordpress
VendorProductVersionCPE
expresstechquiz_and_survey_master*cpe:2.3:a:expresstech:quiz_and_survey_master:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "quiz-master-next",
    "product": "Quiz And Survey Master",
    "vendor": "ExpressTech",
    "versions": [
      {
        "changes": [
          {
            "at": "8.2.3",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "8.2.2",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

AI Score

9.1

Confidence

High

EPSS

0

Percentile

9.0%