Vulnerabilities
Vulnerable Software
Expresstech:  Security Vulnerabilities
php/qmn_options_questions_tab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant stored XSS, via the question_name parameter because js/admin_question.js mishandles parsing inside of a SCRIPT element.
CVSS Score
6.5
EPSS Score
0.01
Published
2020-08-16
The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter (and/or the quiz_id parameter). The component is: admin/quiz-options-page.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.
CVSS Score
6.1
EPSS Score
0.017
Published
2019-12-13
The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface.
CVSS Score
8.8
EPSS Score
0.006
Published
2019-08-14


Contact Us

Shodan ® - All rights reserved