CVE-2023-0291
09.06.2023, 06:15
The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJAX action in versions up to, and including, 8.0.8. This makes it possible for unauthenticated attackers to delete arbitrary media files.Enginsight
Vendor | Product | Version |
---|---|---|
expresstech | quiz_and_survey_master | 𝑥 ≤ 8.0.8 |
𝑥
= Vulnerable software versions
References