Show filters
221 Total Results
Displaying 101-110 of 221
Sort by:
Attacker Value
Unknown
CVE-2021-24764
Disclosure Date: February 01, 2022 (last updated February 23, 2025)
The Perfect Survey WordPress plugin before 1.5.2 does not sanitise and escape multiple parameters (id and filters[session_id] of single_statistics page, type and message of importexport page) before outputting them back in pages/attributes in the admin dashboard, leading to Reflected Cross-Site Scripting issues
0
Attacker Value
Unknown
CVE-2021-24763
Disclosure Date: February 01, 2022 (last updated February 23, 2025)
The Perfect Survey WordPress plugin before 1.5.2 does not have proper authorisation nor CSRF checks in the save_global_setting AJAX action, allowing unauthenticated users to edit surveys and modify settings. Given the lack of sanitisation and escaping in the settings, this could also lead to a Stored Cross-Site Scripting issue which will be executed in the context of a user viewing any survey
0
Attacker Value
Unknown
CVE-2021-24762
Disclosure Date: February 01, 2022 (last updated February 23, 2025)
The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.
0
Attacker Value
Unknown
CVE-2021-41609
Disclosure Date: January 28, 2022 (last updated February 23, 2025)
SQL injection in the ID parameter of the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve data from the application's backend database via boolean-based blind and UNION injection.
0
Attacker Value
Unknown
CVE-2021-41608
Disclosure Date: January 28, 2022 (last updated February 23, 2025)
A file disclosure vulnerability in the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve survey user submitted data by modifying the value of the ID parameter in sequential order beginning from 1.
0
Attacker Value
Unknown
CVE-2022-0182
Disclosure Date: January 17, 2022 (last updated February 23, 2025)
Stored cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote authenticated attacker to inject an arbitrary script via an website that uses Quiz And Survey Master.
0
Attacker Value
Unknown
CVE-2022-0181
Disclosure Date: January 17, 2022 (last updated February 23, 2025)
Reflected cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to inject an arbitrary script via unspecified vectors.
0
Attacker Value
Unknown
CVE-2022-0180
Disclosure Date: January 17, 2022 (last updated February 23, 2025)
Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially crafted web page.
0
Attacker Value
Unknown
CVE-2018-10228
Disclosure Date: December 14, 2021 (last updated February 23, 2025)
Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows remote attackers to inject arbitrary web script or HTML via the changes_cp parameter to the index.php/admin/themes/sa/templatesavechanges URI.
0
Attacker Value
Unknown
CVE-2021-24718
Disclosure Date: December 06, 2021 (last updated February 23, 2025)
The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
0