CVE-2023-6166

Severity
6.1MEDIUM
EPSS
0.1%
top 69.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 26

Description

The Quiz Maker WordPress plugin before 6.4.9.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

CVEListV5unknown/quiz_maker< 6.4.9.5
NVDays-pro/quiz_maker< 6.4.9.5

🔴Vulnerability Details

3
CVEList
Quiz Maker < 6.4.9.5 - Reflected Cross-Site Scripting2023-12-26
GHSA
GHSA-8fxj-9pc3-pv45: The Quiz Maker WordPress plugin before 62023-12-26
OSV
libcap2 vulnerability2023-06-19
CVE-2023-6166 (MEDIUM CVSS 6.1) | The Quiz Maker WordPress plugin bef | cvebase.io