CVE-2020-35949
Summary
| CVE | CVE-2020-35949 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-01 04:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution. If a quiz question could be answered by uploading a file, only the Content-Type header was checked during the upload, and thus the attacker could use text/plain for a .php file. |
Risk And Classification
Problem Types: CWE-434
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Expresstech | Quiz And Survey Master | All | All | All | All |
| Application | Expresstech | Quiz And Survey Master | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Quiz and Survey Master < 7.0.1 - Arbitrary File Upload Security Vulnerability | MISC | wpscan.com | Exploit, Third Party Advisory |
| Critical Vulnerabilities Patched in Quiz and Survey Master Plugin | MISC | www.wordfence.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.