What the vulnerability does
01Description
Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.
Explanation of Vulnerability in Simple Terms
Quiz And Survey Master versions up to 11.2.0 contain a SQL injection vulnerability in database query handling. An attacker with low-level user access can inject malicious SQL commands to read sensitive data from the database, including user information and survey responses. The vulnerability also allows limited disruption of site availability. Update to a version newer than 11.2.0.
What an attacker can do
Read sensitive data from the database, including user credentials and survey responses; cause partial site unavailability.
Potential impact on your site
User data and survey responses may be exposed; site performance may degrade. Requires immediate patching.
Conditions required to exploit
Attacker must have a low-level user account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities