Quiz And Survey Master < 7.1.12 - Authenticated SQL injection via shortcode
CVE-2021-24221
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 12 April 2021
What is CVE-2021-24221?
The Quiz And Survey Master β Best Quiz, Exam and Survey Plugin for WordPress plugin before 7.1.12 did not sanitise the result_id GET parameter on pages with the [qsm_result] shortcode without id attribute, concatenating it in a SQL statement and leading to an SQL injection. The lowest role allowed to use this shortcode in post or pages being author, such user could gain unauthorised access to the DBMS. If the shortcode (without the id attribute) is embed on a public page or post, then unauthenticated users could exploit the injection.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Quiz And Survey Master β Best Quiz, Exam and Survey Plugin for WordPress 7.1.12
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved