nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-6025 CVE-2024-6025
MEDIUM
Quiz and Survey Master < 9.0.5 - Contributor+ Stored XSS
Record summary
CVE-2024-6025 has a selected CVSS score of 6.5 (medium).
Description
The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 11, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Quiz and Survey Master (QSM)Default status: unaffected | CVE List | Before 9.0.5 | affected |
quiz_and_survey_masterBrowse expresstech / quiz_and_survey_masterDefault status: unaffected | CVE List | Before 9.0.5 | affected |
References
2wpscan.comexploitvdb entryTechnical description
https://wpscan.com/vulnerability/15abc7dd-95b1-4dad-ba25-eb65105d3925