CVE-2020-35949: Malicious File Upload
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution. If a quiz question could be answered by uploading a file, only the Content-Type header was checked during the upload, and thus the attacker could use text/plain for a .php file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-35949?
CVE-2020-35949 is a critical vulnerability in the Quiz and Survey Master plugin for WordPress, allowing unauthenticated attackers to upload arbitrary files and achieve remote code execution.
How severe is CVE-2020-35949?
CVE-2020-35949 has a severity rating of 9.8 (Critical).
What is the affected software by CVE-2020-35949?
The affected software is the Quiz and Survey Master plugin for WordPress version up to 7.0.1.
How can an unauthenticated attacker exploit CVE-2020-35949?
An unauthenticated attacker can exploit CVE-2020-35949 by uploading arbitrary files and achieving remote code execution if a quiz question can be answered by uploading a file.
Are there any references available for CVE-2020-35949?
Yes, you can refer to the following links for more information on CVE-2020-35949: 1. [WPScan](https://wpscan.com/vulnerability/10349) 2. [Wordfence Blog](https://www.wordfence.com/blog/2020/08/critical-vulnerabilities-patched-in-quiz-and-survey-master-plugin/)