cleantalk
Vulnerabilities and Security Researches

Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress, 44bce76b-e3a8-4afc-ab0e-6d82372ba7cd

Published on
-
Research Description
Quiz and Survey Master (QSM) – Quiz Maker &amp; Survey Maker [quiz-master-next] < 7.1.19 Quiz And Survey Master &lt; 7.1.19 - Unauthenticated Stored Cross-Site Scripting (XSS) When the &quot;Disable collecting and storing IP addresses?&quot; setting is not used, the plugin retrieves the IP address of the submitting user via various methods, such as $_SERVER[&#039;REMOTE_ADDR&#039;] but also arbitrary headers which can be tampered with. The final IP is not sanitised or validated, before being output in the results table in the admin dashboard, leading to a Stored Cross-Site Scripting issue. This could allow unauthenticated attacker to submit a malicious result containing an XSS payload, which will be triggered when an administrator will view the result table.
Affected versions
max 7.1.19.
Status
vulnerable