CVE-2024-6390

The Quiz and Survey Master (QSM) WordPress plugin before 9.1.0 does not properly sanitise and escape some of its Quizz settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks
Configurations

No configuration.

History

05 Aug 2024, 14:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9

05 Aug 2024, 12:41

Type Values Removed Values Added
Summary
  • (es) El complemento Quiz and Survey Master (QSM) de WordPress anterior a 9.1.0 no sanitiza adecuadamente ni escapa a algunas de sus configuraciones de Quizz, lo que podrĂ­a permitir a usuarios con altos privilegios, como el colaborador, realizar ataques de Cross-Site Scripting Almacenado.

03 Aug 2024, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-03 06:16

Updated : 2024-08-05 14:35


NVD link : CVE-2024-6390

Mitre link : CVE-2024-6390

CVE.ORG link : CVE-2024-6390


JSON object : View

Products Affected

No product.

CWE

No CWE.