ZeroHour

CVE-2018-14502

PoC
CVSS 3.1
9.8 critical
EPSS
3%p85
Published
()
Modified
Description

controllers/quizzes.php in the Kiboko Chained Quiz plugin before 1.0.9 for WordPress allows remote unauthenticated users to execute arbitrary SQL commands via the 'answer' and 'answers' parameters.

Vendors
kibokolabs
Products
chained quiz
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.