vendor:
Chained Quiz
by:
Çlirim Emini
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Chained Quiz
Affected Version From: 1.0.8 and below
Affected Version To: 1.0.9
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:chained_quiz
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2020
WordPress Plugin Chained Quiz 1.0.8 – ‘answer’ SQL Injection
WordPress Plugin Plugin Chained Quiz before 1.0.9 allows remote unauthenticated users to execute arbitrary SQL commands via the 'answer' and 'answers' parameters. Chained Quiz appears to be vulnerable to time-based SQL-Injection. The issue lies on the $answer backend variable.
Mitigation:
Upgrade to version 1.0.9 or later