Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress, 44bce76b-e3a8-4afc-ab0e-6d82372ba7cd
- CVE, Research URL
- Home page URL
-
Security reports for Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress
- Published on
- -
- Research Description
- Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker [quiz-master-next] < 7.1.19 Quiz And Survey Master < 7.1.19 - Unauthenticated Stored Cross-Site Scripting (XSS) When the "Disable collecting and storing IP addresses?" setting is not used, the plugin retrieves the IP address of the submitting user via various methods, such as $_SERVER['REMOTE_ADDR'] but also arbitrary headers which can be tampered with. The final IP is not sanitised or validated, before being output in the results table in the admin dashboard, leading to a Stored Cross-Site Scripting issue. This could allow unauthenticated attacker to submit a malicious result containing an XSS payload, which will be triggered when an administrator will view the result table.
- Affected versions
-
max 7.1.19.
- Status
-
vulnerable