CVE-2021-24368
Description
The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its result_id parameter when displaying an existing quiz result page, leading to a reflected Cross-Site Scripting issue. This could allow for privilege escalation by inducing a logged in admin to open a malicious link
CWE
- CWE-79 — CWE-79 Cross-site Scripting (XSS)
Affected
- ExpressTech / Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress — v=7.1.18 <7.1.18 [affected]
CVSS
- (none)
References
- https://wpscan.com/vulnerability/7f2fda5b-45a5-4fc6-968f-90bc9674c999 x_refsource_CONFIRM
Source
cvelistV5-main/cves/2021/24xxx/CVE-2021-24368.json