Quiz And Survey Master <= 8.1.10 - Excessive Quiz Attempts
2023-07-17 00:00
qilin_99Strategic Overview
StatusPatched in 8.1.11
Affected PluginQuiz and Survey Master (QSM) – Quiz Maker & Survey Maker
Affected Version
<= 8.1.10CVSS5.3Medium
CVE
CVE-2023-37984Vulnerability Overview
The Quiz And Survey Master plugin for WordPress is vulnerable to exessive quiz attempts due to a missing validation checks on the ajax_submit_results() function in versions up to, and including, 8.1.10. This makes it possible for unauthenticated attackers to bypass the set limits for the number of times a user can attempt a quiz.
Technical Analysis
REMEDIATION: Update to version 8.1.11, or a newer patched version --- IDENTIFIER: CWE-799 (Improper Control of Interaction Frequency) The product does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C