What the vulnerability does
01Description
Improper Encoding or Escaping of Output vulnerability in Ays Pro Poll Maker poll-maker.This issue affects Poll Maker: from n/a through < 5.5.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Improper Encoding or Escaping of Output vulnerability in Ays Pro Poll Maker poll-maker.This issue affects Poll Maker: from n/a through < 5.5.5.
Explanation of Vulnerability in Simple Terms
Poll Maker versions up to 5.5.5 contain an input validation flaw that allows attackers to modify poll data without authentication. The vulnerability requires no user interaction and can be exploited over the network. Site administrators should update to a version newer than 5.5.5 to prevent unauthorized poll manipulation.
What an attacker can do
Modify poll content and settings without logging in.
Potential impact on your site
Attackers can alter poll questions, answers, or results, potentially spreading misinformation or disrupting user engagement.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities