CVE-2021-36865
WordPress Quiz And Survey Master plugin <= 7.3.4 - Insecure direct object references (IDOR) vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPress allows attackers to change the content of the quiz.
Una vulnerabilidad de referencias directas a objetos inseguros (IDOR) en el plugin ExpressTech Quiz And Survey Master versiones anteriores a 7.3.4 incluyéndola en WordPress, permite a atacantes cambiar el contenido del cuestionario
The Quiz And Survey Master plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and including, 7.3.4. This is due to insufficient validation on the key controlling a quiz's id. This makes it possible for authenticated attackers with author-level capabilities and above to change arbitrary quiz content.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-07-19 CVE Reserved
- 2022-09-29 CVE Published
- 2024-09-17 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
References (2)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Quizandsurveymaster Search vendor "Quizandsurveymaster" | Quiz And Survey Master Search vendor "Quizandsurveymaster" for product "Quiz And Survey Master" | <= 7.3.4 Search vendor "Quizandsurveymaster" for product "Quiz And Survey Master" and version " <= 7.3.4" | wordpress |
Affected
|