Show filters
221 Total Results
Displaying 71-80 of 221
Sort by:
Attacker Value
Unknown
CVE-2023-28313
Disclosure Date: April 11, 2023 (last updated January 11, 2025)
Microsoft Dynamics 365 Customer Voice Cross-Site Scripting Vulnerability
0
Attacker Value
Unknown
CVE-2023-29492
Disclosure Date: April 11, 2023 (last updated September 27, 2024)
Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.
0
Attacker Value
Unknown
CVE-2023-1946
Disclosure Date: April 07, 2023 (last updated October 08, 2023)
A vulnerability was found in SourceCodester Survey Application System 1.0 and classified as problematic. This issue affects some unknown processing of the component Add New Handler. The manipulation of the argument Title with the input <script>prompt(document.domain)</script> leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-225329 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2022-46862
Disclosure Date: February 14, 2023 (last updated November 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.7 versions.
0
Attacker Value
Unknown
CVE-2022-48010
Disclosure Date: January 27, 2023 (last updated November 08, 2023)
LimeSurvey v5.4.15 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /index.php/surveyAdministration/rendersidemenulink?subaction=surveytexts. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description or Welcome-message text fields. NOTE: the vendor indicates that this is not a vulnerability because the manipulation requires Superadministrator privileges, and Superadministrators are already allowed to customize surveys with JavaScript as they wish.
0
Attacker Value
Unknown
CVE-2022-48008
Disclosure Date: January 27, 2023 (last updated October 08, 2023)
An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.
0
Attacker Value
Unknown
CVE-2023-23490
Disclosure Date: January 20, 2023 (last updated October 08, 2023)
The Survey Maker WordPress Plugin, version < 3.1.2, is affected by an authenticated SQL injection vulnerability in the 'surveys_ids' parameter of its 'ays_surveys_export_json' action.
0
Attacker Value
Unknown
CVE-2023-0038
Disclosure Date: January 03, 2023 (last updated October 08, 2023)
The "Survey Maker – Best WordPress Survey Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via survey answers in versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts when submitting quizzes that will execute whenever a user accesses the submissions page.
0
Attacker Value
Unknown
CVE-2022-4033
Disclosure Date: November 29, 2022 (last updated February 24, 2025)
The Quiz and Survey Master plugin for WordPress is vulnerable to input validation bypass via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input validation that allows attackers to inject content other than the specified value (i.e. a number, file path, etc..). This makes it possible attackers to submit values other than the intended input type.
0
Attacker Value
Unknown
CVE-2022-4032
Disclosure Date: November 29, 2022 (last updated February 24, 2025)
The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input sanitization and output escaping that allowed iframe tags to be injected. This makes it possible for unauthenticated attackers to inject iFrames in pages that will execute whenever a user accesses an injected page.
0