First published: Thu Apr 17 2025(Updated: )
Deserialization of Untrusted Data vulnerability in ssvadim SS Quiz allows Object Injection. This issue affects SS Quiz: from n/a through 2.0.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
ssvadim SS Quiz | <=2.0.5 | |
WordPress SS Quiz Plugin | <=2.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27287 is a critical vulnerability that involves deserialization of untrusted data, allowing for object injection.
To mitigate CVE-2025-27287, update your SS Quiz software to version 2.0.6 or higher.
CVE-2025-27287 could allow attackers to exploit object injection for unauthorized actions in affected versions of SS Quiz.
CVE-2025-27287 affects SS Quiz versions up to and including 2.0.5.
The vendor for the affected software is ssvadim, specifically for the SS Quiz product.