CVE-2022-4032: Quiz and Survey Master <= 8.0.4 - Unauthenticated iFrame Injection via Paragraph and Short Answer
The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input sanitization and output escaping that allowed iframe tags to be injected. This makes it possible for unauthenticated attackers to inject iFrames in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-4032?
CVE-2022-4032 is a vulnerability in the Quiz and Survey Master plugin for WordPress that allows for iFrame Injection via the 'question[id]' parameter.
What is the severity of CVE-2022-4032?
The severity of CVE-2022-4032 is high with a CVSS score of 6.1.
How does CVE-2022-4032 affect the Quiz and Survey Master plugin?
CVE-2022-4032 affects the Quiz and Survey Master plugin by allowing unauthenticated attackers to inject iframe tags via the 'question[id]' parameter.
How can CVE-2022-4032 be exploited?
CVE-2022-4032 can be exploited by submitting malicious input via the 'question[id]' parameter and injecting iframe tags.
Is there a fix for CVE-2022-4032?
Yes, upgrading to version 8.0.5 or later of the Quiz and Survey Master plugin fixes CVE-2022-4032.