Deserialization of Untrusted Data Vulnerability in ExpressTech Systems Quiz And Survey Master
CVE-2025-49401
9.8CRITICAL
What is CVE-2025-49401?
A vulnerability exists in the Quiz And Survey Master plugin by ExpressTech Systems, where untrusted data deserialization can lead to object injection risks. This weakness impacts versions from n/a to 10.2.5, enabling potential attackers to exploit the system by injecting malicious objects, thus compromising application integrity and security. Users are encouraged to update to the latest version to mitigate this threat.
Affected Version(s)
Quiz And Survey Master <= 10.2.5
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Phat RiO - BlueRock (Patchstack Alliance)