Record summary

CVE-2023-28787 has a selected CVSS score of 9.3 (critical); EIP currently links 1 Nuclei template.

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.4.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Quiz And Survey Master

Browse ExpressTech / Quiz And Survey Masterquiz-master-next

Default status: unaffected

CVE ListThrough 8.1.4affected

Nuclei templates

1
ProjectDiscoveryCRITICALQuiz and Survey Master <= 8.1.4 - SQL InjectionCVSS 8.6

ExpressTech Quiz And Survey Master (versions up to 8.1.4) contains an SQL injection caused by improper neutralization of special elements used in SQL commands, letting attackers execute arbitrary SQL queries, exploit requires user interaction.

Impact

Attackers can execute arbitrary SQL commands, potentially leading to data theft, data tampering, or database compromise.

Remediation

Update to the latest version of Quiz And Survey Master that addresses this vulnerability.

WeaknessesCWE-89
AuthorsShivam Kamboj
Template tagscvecve2023wordpresswpwp-pluginsqliquiz-master-nextqsm
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
FOFA: body="/quiz-master-next"

Source: ProjectDiscovery

References

2