First published: Sun Jun 04 2023(Updated: )
A vulnerability was found in Watu Quiz Plugin up to 2.6.7 on WordPress. It has been rated as critical. This issue affects the function watu_exams of the file controllers/exam.php of the component Exam Handler. The manipulation of the argument quiz leads to sql injection. The attack may be initiated remotely. Upgrading to version 2.6.8 is able to address this issue. The name of the patch is bf42e7cfd819a3e76cf3e1465697e89f4830590c. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-230651.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Kibokolabs Watu Quiz | <2.6.8 | |
<2.6.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-10111 is critical with a CVSS score of 9.8.
The affected software of CVE-2015-10111 is the Watu Quiz Plugin up to version 2.6.7 on WordPress.
The vulnerability in CVE-2015-10111 is an SQL injection vulnerability in the watu_exams function of the Exam Handler component.
The SQL injection vulnerability in CVE-2015-10111 can be exploited by manipulating the quiz argument in the watu_exams function.
Yes, a fix is available for CVE-2015-10111. Users should update to Watu Quiz Plugin version 2.6.8 or later.