nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-4032 CVE-2022-4032
HIGH
Quiz and Survey Master <= 8.0.4 - Unauthenticated iFrame Injection via Paragraph and Short Answer
Record summary
CVE-2022-4032 has a selected CVSS score of 7.2 (high).
Description
The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input sanitization and output escaping that allowed iframe tags to be injected. This makes it possible for unauthenticated attackers to inject iFrames in pages that will execute whenever a user accesses an injected page.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 23, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Quiz and Survey Master (QSM) – Easy Quiz and Survey MakerBrowse expresstech / Quiz and Survey Master (QSM) – Easy Quiz and Survey MakerDefault status: unaffected | CVE List | Through 8.0.4 | affected |
References
4plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2801761%40quiz-master-next&new=2801761%40quiz-master-next&sfp_email=&sfph_mail= wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/b901b3f8-8bbd-42ef-8e0c-de6d09c4950f?source=cve wordfence.com
https://www.wordfence.com/vulnerability-advisories-continued