CVE-2022-0182: XSS
Published Jan 17, 2022
·Updated
Stored cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote authenticated attacker to inject an arbitrary script via an website that uses Quiz And Survey Master.
Affected Software
1 affected component
ExpressTech Quiz And Survey Master<7.3.7
Event History
Jan 17, 2022
CVE Published
via MITRE·09:10 AM
Data Sourced
via MITRE·09:10 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-0182?
CVE-2022-0182 is a stored cross-site scripting vulnerability in Quiz And Survey Master.
2
How does CVE-2022-0182 affect Quiz And Survey Master?
CVE-2022-0182 affects versions of Quiz And Survey Master prior to 7.3.7.
3
What is the severity of CVE-2022-0182?
The severity of CVE-2022-0182 is medium with a CVSS score of 5.4.
4
How can a remote authenticated attacker exploit CVE-2022-0182?
A remote authenticated attacker can exploit CVE-2022-0182 by injecting an arbitrary script via a website that uses Quiz And Survey Master.
5
How can I fix CVE-2022-0182?
To fix CVE-2022-0182, update Quiz And Survey Master to version 7.3.7 or newer.