Show filters
221 Total Results
Displaying 61-70 of 221
Sort by:
Attacker Value
Unknown
CVE-2023-26524
Disclosure Date: November 13, 2023 (last updated November 17, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.10 versions.
0
Attacker Value
Unknown
CVE-2023-40980
Disclosure Date: September 01, 2023 (last updated October 08, 2023)
File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/UploadAction.java file.
0
Attacker Value
Unknown
CVE-2023-3575
Disclosure Date: August 07, 2023 (last updated October 08, 2023)
The Quiz And Survey Master WordPress plugin before 8.1.11 does not properly sanitize and escape question titles, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks
0
Attacker Value
Unknown
CVE-2022-46484
Disclosure Date: August 02, 2023 (last updated October 08, 2023)
Information disclosure in password protected surveys in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and below allows attackers to view the password to access and arbitrarily submit surveys.
0
Attacker Value
Unknown
CVE-2022-46485
Disclosure Date: August 02, 2023 (last updated October 08, 2023)
Data Illusion Survey Software Solutions ngSurvey version 2.4.28 and below is vulnerable to Denial of Service if a survey contains a "Text Field", "Comment Field" or "Contact Details".
0
Attacker Value
Unknown
CVE-2023-38057
Disclosure Date: July 24, 2023 (last updated October 08, 2023)
An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject javascript code in free text answers. This allows a cross site scripting attack while reading the replies as authenticated agent.
This issue affects OTRS Survey module from 7.0.X before 7.0.32, from 8.0.X before 8.0.13 and ((OTRS)) Community Edition Survey module from 6.0.X through 6.0.22.
0
Attacker Value
Unknown
CVE-2020-20070
Disclosure Date: June 20, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability found in wkeyuan DWSurvey 1.0 allows a remote attacker to execute arbitrary code via thequltemld parameter of the qu-multi-fillblank!answers.action file.
0
Attacker Value
Unknown
CVE-2023-0292
Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.8. This is due to missing nonce validation on the function associated with the qsm_remove_file_fd_question AJAX action. This makes it possible for unauthenticated attackers to delete arbitrary media files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2023-0291
Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJAX action in versions up to, and including, 8.0.8. This makes it possible for unauthenticated attackers to delete arbitrary media files.
0
Attacker Value
Unknown
CVE-2023-2572
Disclosure Date: June 05, 2023 (last updated October 08, 2023)
The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
0