vendor:
Perfect Survey
by:
Ron Jost (Hacker5preme)
9.8
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: Perfect Survey
Affected Version From: < 1.5.2
Affected Version To: 1.5.2001
Patch Exists: YES
Related CWE: CVE-2021-24762
CPE: a:getperfectsurvey:perfect_survey:1.5.1
Tags: cve,wpscan,cve2021,sqli,wp,wordpress,wp-plugin,unauth,edb
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Nuclei Metadata: {'max-request': 1, 'framework': 'wordpress', 'vendor': 'getperfectsurvey', 'product': 'perfect_survey'}
Platforms Tested: Ubuntu 20.04
2022
WordPress Plugin Perfect Survey – 1.5.1 – SQLi (Unauthenticated)
The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.
Mitigation:
Upgrade to version 1.5.2 or later.