Savsoft Quiz
cpe:2.3:a:savsoft_technologies:savsoft_quiz:*:*:*:*:*:*:*
- <= 5.0
A persistent cross-site scripting vulnerability has been identified in Savsoft Quiz version 5.0. This vulnerability resides in the user account settings page, where authenticated attackers can inject malicious HTML and JavaScript. The injected scripts are executed in the browsers of users who view the affected profile after the injection.
Exploitation of this vulnerability allows for persistent cross-site scripting, where injected scripts are executed in the context of the user viewing the profile.
To reproduce this vulnerability, log into an account on Savsoft Quiz 5.0. Navigate to the 'My Account' section and insert a script payload into the profile fields. After submitting, the injected script will execute, demonstrating the cross-site scripting vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.