First published: Tue Mar 10 2020(Updated: )
controllers/quizzes.php in the Kiboko Chained Quiz plugin before 1.0.9 for WordPress allows remote unauthenticated users to execute arbitrary SQL commands via the 'answer' and 'answers' parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kibokolabs Chained Quiz Wordpress | <1.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-14502.
The title of this vulnerability is controllers/quizzes.php in the Kiboko Chained Quiz plugin before 1.0.9 for WordPress allows remote u…
The severity of CVE-2018-14502 is critical, with a severity value of 9.8.
The Kiboko Chained Quiz plugin before version 1.0.9 for WordPress is affected by CVE-2018-14502.
Remote unauthenticated users can exploit CVE-2018-14502 by executing arbitrary SQL commands via the 'answer' and 'answers' parameters.