Vulnerabilities > Expresstech > Quiz AND Survey Master > 7.1.2

DATE CVE VULNERABILITY TITLE RISK
2021-04-12 CVE-2021-24221 SQL Injection vulnerability in Expresstech Quiz and Survey Master
The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin before 7.1.12 did not sanitise the result_id GET parameter on pages with the [qsm_result] shortcode without id attribute, concatenating it in a SQL statement and leading to an SQL injection.
network
low complexity
expresstech CWE-89
8.8