CVE-2023-28787
WordPress Quiz And Survey Master plugin <= 8.1.4 - Unauthenticated SQL Injection vulnerability
Record summary
CVE-2023-28787 has a selected CVSS score of 9.3 (critical); EIP currently links 1 Nuclei template.
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.4.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Through 8.1.4 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALQuiz and Survey Master <= 8.1.4 - SQL InjectionCVSS 8.6
ExpressTech Quiz And Survey Master (versions up to 8.1.4) contains an SQL injection caused by improper neutralization of special elements used in SQL commands, letting attackers execute arbitrary SQL queries, exploit requires user interaction.
Impact
Attackers can execute arbitrary SQL commands, potentially leading to data theft, data tampering, or database compromise.
Remediation
Update to the latest version of Quiz And Survey Master that addresses this vulnerability.
Source: ProjectDiscovery