CVE-2020-35951
Quiz and Survey Master <= 7.0.0 - Unauthenticated Arbitrary File Deletion
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offline and allow an attacker to reinstall with a WordPress instance under their control. This occurred via qsm_remove_file_fd_question, which allowed unauthenticated deletions (even though it was only intended for a person to delete their own quiz-answer files).
Se detectó un problema en el plugin Quiz and Survey Master versiones anteriores a 7.0.1 para WordPress. Permite a los usuarios eliminar archivos arbitrarios, como el archivo wp-config.php, que podría desconectar un sitio de manera efectiva y permitir a un atacante reinstalarlo con una instancia de WordPress bajo su control. Esto ocurrió por medio de la función qsm_remove_file_fd_question, que permitió eliminaciones no autenticadas (aunque solo estaba destinado a que una persona eliminara sus propios archivos de respuestas de cuestionarios).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-08-03 CVE Published
- 2021-01-01 CVE Reserved
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-306: Missing Authentication for Critical Function
- CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/10348 | 2024-08-04 | |
https://www.wordfence.com/blog/2020/08/critical-vulnerabilities-patched-in-quiz-and-survey-master-plugin | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Expresstech Search vendor "Expresstech" | Quiz And Survey Master Search vendor "Expresstech" for product "Quiz And Survey Master" | < 7.0.1 Search vendor "Expresstech" for product "Quiz And Survey Master" and version " < 7.0.1" | wordpress |
Affected
|