vendor:
Quiz
by:
S@BUN
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Quiz
Affected Version From: 0.81
Affected Version To: 0.81
Patch Exists: YES
Related CWE: N/A
CPE: a:ioannis_sannos:quiz
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Joomla
2008
Joomla SQL Injection(com_quiz)user_tst_shw
An attacker can exploit this vulnerability by adding malicious code to the 'tid' parameter in the URL. This malicious code can be used to extract the username and password of the users from the database.
Mitigation:
The vendor has released an update to address this vulnerability. Users are advised to update to the latest version.