Lucene search

K

Savsoft Quiz Security Vulnerabilities

cve
cve

CVE-2014-100025

Cross-site request forgery (CSRF) vulnerability in index.php/user_data/insert_user in Savsoft Quiz allows remote attackers to hijack the authentication of administrators for requests that create an administrator account via a crafted request.

7.2AI Score

0.004EPSS

2015-01-13 03:59 PM
22
cve
cve

CVE-2020-24609

TechKshetra Info Solutions Pvt. Ltd Savsoft Quiz 5.5 and earlier has XSS which can result in an attacker injecting the XSS payload in the User Registration section and each time the admin visits the manage user section from the admin panel, the XSS triggers and the attacker can steal the cookie via...

6.1CVSS

5.9AI Score

0.002EPSS

2020-08-25 03:15 PM
46
cve
cve

CVE-2020-27515

A Cross Site Scripting (XSS) vulnerability in Savsoft Quiz v5.0 allows remote attackers to inject arbitrary web script or HTML via the Skype ID field.

6.1CVSS

5.9AI Score

0.009EPSS

2020-12-26 02:15 AM
67
1
cve
cve

CVE-2020-35349

Savsoft Quiz 5 is affected by: Cross Site Scripting (XSS) via field_title (aka a title on the custom fields page).

4.8CVSS

5AI Score

0.001EPSS

2020-12-26 04:15 AM
65
1