Lucene search

K
vulnrichmentWPScanVULNRICHMENT:CVE-2024-5606
HistoryJul 02, 2024 - 6:00 a.m.

CVE-2024-5606 Quiz And Survey Master < 9.0.2 - Contributor+ SQLi

2024-07-0206:00:03
WPScan
github.com
1
wordpress
plugin
sql injection
vulnerable
ajax action
contributors

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

19.5%

SSVC

Exploitation

poc

Automatable

no

Technical Impact

total

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action, leading to a SQL injection exploitable by Contributors and above role

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:expresstech:quiz_and_survey_master:*:*:*:*:*:wordpress:*:*"
    ],
    "vendor": "expresstech",
    "product": "quiz_and_survey_master",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "9.0.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

19.5%

SSVC

Exploitation

poc

Automatable

no

Technical Impact

total

Related for VULNRICHMENT:CVE-2024-5606