vendor:
Savsoft Quiz Enterprise
by:
Hemant Patidar (HemantSolo)
7.5
CVSS
HIGH
Stored Cross-site scripting(XSS)
79
CWE
Product Name: Savsoft Quiz Enterprise
Affected Version From: 5.0
Affected Version To: 5.5
Patch Exists: YES
Related CWE: N/A
CPE: a:savsoft:savsoft_quiz_enterprise:5.5
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10/Kali Linux
2020
Savsoft Quiz Enterprise Version 5.5 – Persistent Cross-Site Scripting
This vulnerability can results attacker to inject the XSS payload in User Registration section and each time admin visits the manage user section from admin panel, the XSS triggers and attacker can able to steal the cookie according to the crafted payload.
Mitigation:
Input validation, Output encoding, Content Security Policy (CSP)