CVE-2019-17599
Quiz And Survey Master <= 6.3.4 - Reflected Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter (and/or the quiz_id parameter). The component is: admin/quiz-options-page.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.
El plugin quiz-master-next (también se conoce como Quiz And Survey Master) versiones anteriores a 6.3.5 para WordPress, está afectado por: Cross Site Scripting (XSS). El impacto es: permite a un atacante ejecutar código arbitrario HTML y JavaScript por medio del parámetro from o till (y/o el parámetro quiz_id). El componente es: el archivo admin/quiz-options-page.php. El vector de ataque es: cuando el administrador inicia sesión, un XSS reflejado puede ser ejecutado con un clic en una URL maliciosa.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-10-15 CVE Reserved
- 2019-11-13 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/QuizandSurveyMaster/quiz_master_next/pull/796 | Third Party Advisory | |
https://wordpress.org/plugins/quiz-master-next/#developers | Release Notes |
URL | Date | SRC |
---|---|---|
https://github.com/QuizandSurveyMaster/quiz_master_next/issues/795 | 2024-08-05 | |
https://wpvulndb.com/vulnerabilities/9977 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Expresstech Search vendor "Expresstech" | Quiz And Survey Master Search vendor "Expresstech" for product "Quiz And Survey Master" | < 6.3.5 Search vendor "Expresstech" for product "Quiz And Survey Master" and version " < 6.3.5" | wordpress |
Affected
|