CVE-2020-35951
65Vexday Risk Score
Corrija em breve. Ela tem exploit funcional público.
ssvc Attendcvss 9.9epss 76%
probabilidade de exploração
76%top 1% das CVEs
exploração observada
nãonenhuma fonte reporta
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offline and allow an attacker to reinstall with a WordPress instance under their control. This occurred via qsm_remove_file_fd_question, which allowed unauthenticated deletions (even though it was only intended for a person to delete their own quiz-answer files).
CVSS:3.1/AC:L/AV:N/A:H/C:L/I:L/PR:N/S:C/UI:N
Produtos afetados
n/a · n/a