571
VMScore

CVE-2020-35951

Published: 01/01/2021 Updated: 21/07/2021
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.9 | Impact Score: 5.3 | Exploitability Score: 3.9
VMScore: 571
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

An issue exists in the Quiz and Survey Master plugin prior to 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offline and allow an malicious user to reinstall with a WordPress instance under their control. This occurred via qsm_remove_file_fd_question, which allowed unauthenticated deletions (even though it was only intended for a person to delete their own quiz-answer files).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

expresstech quiz and survey master

Vendor Advisories

Check Point Reference: CPAI-2020-4142 Date Published: 6 Mar 2024 Severity: Critical ...