Quiz and Survey Master <= 7.0.0 - Arbitrary File Upload
2020-08-03 00:00
Chloe ChamberlandStrategic Overview
StatusPatched in 7.0.1
Affected PluginQuiz and Survey Master (QSM) – Quiz Maker & Survey Maker
Affected Version
< 7.0.1CVSS9.8Critical
CVE
CVE-2020-35949Vulnerability Overview
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution. If a quiz question could be answered by uploading a file, only the Content-Type header was checked during the upload, and thus the attacker could use text/plain for a .php file.
Technical Analysis
REMEDIATION: Update to version 7.0.1, or a newer patched version --- IDENTIFIER: CWE-434 (Unrestricted Upload of File with Dangerous Type) The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C