What the vulnerability does
01Description
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in ARI Soft ARI Stream Quiz allows Code Injection.This issue affects ARI Stream Quiz: from n/a through 1.3.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in ARI Soft ARI Stream Quiz allows Code Injection.This issue affects ARI Stream Quiz: from n/a through 1.3.2.
Explanation of Vulnerability in Simple Terms
ARI Stream Quiz versions up to 1.3.2 contain a cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious scripts. An attacker with low-level access can modify quiz content or settings to execute code in other users' browsers, potentially stealing session data or performing actions on their behalf. The vulnerability requires an authenticated account but no user interaction from the victim.
What an attacker can do
Inject malicious scripts into quiz content that execute in other users' browsers.
Potential impact on your site
Quiz data and user sessions are at risk; attackers with basic access can compromise other users.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the site.
Key dates
External resources
Related vulnerabilities