ZeroHour

CVE-2024-6025

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p31
Published
()
Modified
Description

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks

Vendors
expresstech
Products
quiz and survey master
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.