An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution. If a quiz question could be answered by uploading a file, only the Content-Type header was checked during the upload, and thus the attacker could use text/plain for a .php file.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-01-01T03:27:33

Updated: 2021-01-01T03:27:33

Reserved: 2021-01-01T00:00:00


Link: CVE-2020-35949

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-01-01T04:15:13.557

Modified: 2021-07-21T11:39:23.747


Link: CVE-2020-35949

JSON object: View

cve-icon Redhat Information

No data.

CWE