The Quiz And Survey Master plugin 6.0.4 for WordPress allows wp-admin/admin.php?page=mlw_quiz_results quiz_id XSS.
References
Link | Resource |
---|---|
https://wordpress.org/plugins/quiz-master-next/#developers | Product Third Party Advisory |
https://security-consulting.icu/blog/2019/02/wordpress-quiz-and-survey-master-xss/ | Exploit Third Party Advisory |
https://lists.openwall.net/full-disclosure/2019/02/05/5 | Exploit Mailing List Third Party Advisory |
https://github.com/QuizandSurveyMaster/quiz_master_next/blob/master/CHANGELOG.md | Release Notes Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-03-05 13:29
Updated : 2019-03-06 05:00
NVD link : CVE-2019-9575
Mitre link : CVE-2019-9575
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
quizandsurveymaster
- quiz_and_survey_master