Описание
The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJAX action in versions up to, and including, 8.0.8. This makes it possible for unauthenticated attackers to delete arbitrary media files.
Ссылки
- Not ApplicableVDB Entry
- Patch
- Product
- Third Party Advisory
- Not ApplicableVDB Entry
- Patch
- Product
- Third Party Advisory
Уязвимые конфигурации
EPSS
7.2 High
CVSS3
9.1 Critical
CVSS3
Дефекты
Связанные уязвимости
The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJAX action in versions up to, and including, 8.0.8. This makes it possible for unauthenticated attackers to delete arbitrary media files.
Уязвимость функции qsm_remove_file_fd_question плагина The Quiz And Survey Master системы управления содержимым сайта WordPress, позволяющая нарушителю удалять произвольные файлы
EPSS
7.2 High
CVSS3
9.1 Critical
CVSS3