What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in ARI Soft ARI Stream Quiz.This issue affects ARI Stream Quiz: from n/a through 1.2.32.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in ARI Soft ARI Stream Quiz.This issue affects ARI Stream Quiz: from n/a through 1.2.32.
Explanation of Vulnerability in Simple Terms
ARI Stream Quiz versions up to 1.2.32 are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unwanted actions on the quiz application without the admin's knowledge or consent. The attack requires the victim to visit the attacker's page while authenticated to the vulnerable site.
What an attacker can do
Perform unwanted actions (modify or delete quiz data) on behalf of a logged-in administrator without their consent.
Potential impact on your site
Administrators' quiz settings, questions, or results could be altered or deleted by attackers through CSRF attacks targeting logged-in users.
Conditions required to exploit
Victim must be logged in to the site and visit an attacker-controlled webpage while authenticated.
Key dates
External resources
Related vulnerabilities