momo安全漏洞库

多模块数据检索平台

登录 注册
返回列表

CVE-2023-28787: Quiz and Survey Master <= 8.1.4 - SQL Injection

CVE: CVE-2023-28787
CNVD: 暂无
CNNVD: 暂无
漏洞类型: SQL注入
漏洞等级: 严重
年份: 2026
POC_ID: 暂无
漏洞描述
ExpressTech Quiz And Survey Master (versions up to 8.1.4) contains an SQL injection caused by improper neutralization of special elements used in SQL commands, letting attackers execute arbitrary SQL queries, exploit requires user interaction. [已公开] id: CVE-2023-28787 info: name: Quiz and Survey Master <= 8.1.4 - SQL Injection author: Shivam Kamboj severity: critical description: | ExpressTech Quiz And Survey Master (versions up to 8.1.4) contains an SQL injection caused by improper neutralization of special elements used in SQL commands, letting attackers execute arbitrary SQL queries, exploit requires user interaction. impact: | Attackers can execute arbitrary SQL commands, potentially leading to data theft, data tampering, or database compromise. remediation: | Update to the latest version of Quiz And Survey Master that addresses this vulnerability. reference: - https://patchstack.com/articles/critical-unauthenticated-sql-injection-in-quiz-and-survey-master/ - https://patchstack.com/database/wordpress/plugin/quiz-master-next/vulnerability/wordpress-quiz-and-survey-master-plugin-8-1-4-unauthenticated-sql-injection-vulnerability - https://nvd.nist.gov/vuln/detail/CVE-2023-28787 cl
影响范围
未知
漏洞详情
登录后可查看漏洞详情。请先 登录注册
漏洞 POC
登录后可查看漏洞 POC。请先 登录注册
修复建议
暂无