CVE-2021-24368: Quiz And Survey Master < 7.1.18 - Reflected Cross-Site Scripting (XSS)
The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its resultid parameter when displaying an existing quiz result page, leading to a reflected Cross-Site Scripting issue. This could allow for privilege escalation by inducing a logged in admin to open a malicious link
Other sources
The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its resultid parameter when displaying an existing quiz result page, leading to a reflected Cross-Site Scripting issue. This could allow for privilege escalation by inducing a logged in admin to open a malicious link
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24368?
CVE-2021-24368 refers to a vulnerability in the Quiz And Survey Master WordPress plugin that allows for reflected cross-site scripting (XSS) attacks.
How does CVE-2021-24368 affect the Quiz And Survey Master plugin?
CVE-2021-24368 affects the Quiz And Survey Master plugin by not properly sanitizing or escaping the result_id parameter, which can lead to a reflected XSS issue.
What is the severity of CVE-2021-24368?
The severity of CVE-2021-24368 is medium, with a severity value of 6.1.
How can CVE-2021-24368 be exploited?
CVE-2021-24368 can be exploited by an attacker inducing a user to click on a maliciously crafted link containing the result_id parameter.
Is there a fix available for CVE-2021-24368?
Yes, updating the Quiz And Survey Master plugin to version 7.1.18 or later will fix the vulnerability.