Savsoft Quiz Persistent Cross-Site Scripting Vulnerability in User Account Settings

Vulnerability

A persistent cross-site scripting vulnerability has been identified in Savsoft Quiz version 5.0. This vulnerability resides in the user account settings page, where authenticated attackers can inject malicious HTML and JavaScript. The injected scripts are executed in the browsers of users who view the affected profile after the injection.

Impact

Exploitation of this vulnerability allows for persistent cross-site scripting, where injected scripts are executed in the context of the user viewing the profile.

Reproduction

To reproduce this vulnerability, log into an account on Savsoft Quiz 5.0. Navigate to the 'My Account' section and insert a script payload into the profile fields. After submitting, the injected script will execute, demonstrating the cross-site scripting vulnerability.

Added: May 15, 2026, 7:45 PM
Updated: May 15, 2026, 7:45 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
1.7
exploitability
6.3
remediation
7.7
relevance
8.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.