CVE-2024-6390: Quiz and Survey Master (QSM) < 9.1.0 - Contributor+ Stored XSS
Published Aug 3, 2024
·Updated
The Quiz and Survey Master (QSM) WordPress plugin before 9.1.0 does not properly sanitise and escape some of its Quizz settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks
Affected Software
2 affected components
Quiz and Survey Master QSM<9.1.0
ExpressTech Quiz And Survey Master Wordpress<9.1.0
Event History
Aug 3, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-6390?
CVE-2024-6390 is classified as a high severity vulnerability due to its potential for stored Cross-Site Scripting attacks.
2
Who is affected by CVE-2024-6390?
CVE-2024-6390 affects users of the Quiz and Survey Master WordPress plugin prior to version 9.1.0.
3
How do I fix CVE-2024-6390?
To fix CVE-2024-6390, update the Quiz and Survey Master plugin to version 9.1.0 or later.
4
What type of attack does CVE-2024-6390 allow?
CVE-2024-6390 allows high privilege users, such as contributors, to perform stored Cross-Site Scripting attacks.
5
What specific feature of the Quiz and Survey Master plugin is affected by CVE-2024-6390?
CVE-2024-6390 specifically affects the sanitization and escaping of certain Quizz settings.