CWE
89
Advisory Published
Updated

CVE-2015-10111: Watu Quiz Plugin Exam exam.php watu_exams sql injection

First published: Sun Jun 04 2023(Updated: )

A vulnerability was found in Watu Quiz Plugin up to 2.6.7 on WordPress. It has been rated as critical. This issue affects the function watu_exams of the file controllers/exam.php of the component Exam Handler. The manipulation of the argument quiz leads to sql injection. The attack may be initiated remotely. Upgrading to version 2.6.8 is able to address this issue. The name of the patch is bf42e7cfd819a3e76cf3e1465697e89f4830590c. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-230651.

Credit: cna@vuldb.com cna@vuldb.com

Affected SoftwareAffected VersionHow to fix
Kibokolabs Watu Quiz<2.6.8
<2.6.8

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2015-10111?

    The severity of CVE-2015-10111 is critical with a CVSS score of 9.8.

  • What is the affected software of CVE-2015-10111?

    The affected software of CVE-2015-10111 is the Watu Quiz Plugin up to version 2.6.7 on WordPress.

  • What is the vulnerability in CVE-2015-10111?

    The vulnerability in CVE-2015-10111 is an SQL injection vulnerability in the watu_exams function of the Exam Handler component.

  • How can the SQL injection vulnerability in CVE-2015-10111 be exploited?

    The SQL injection vulnerability in CVE-2015-10111 can be exploited by manipulating the quiz argument in the watu_exams function.

  • Is there a fix available for CVE-2015-10111?

    Yes, a fix is available for CVE-2015-10111. Users should update to Watu Quiz Plugin version 2.6.8 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203