PT-2022-9459 · WordPress · The Perfect Survey
Apple502J
·
Published
2022-02-01
·
Updated
2022-02-04
·
CVE-2021-24763
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Perfect Survey WordPress plugin versions prior to 1.5.2
Description
The issue is related to the lack of proper authorization and CSRF checks in the
save global setting AJAX action. This allows unauthenticated users to edit surveys and modify settings. Additionally, the lack of sanitization and escaping in the settings could lead to a Stored Cross-Site Scripting issue, which would be executed in the context of a user viewing any survey.Recommendations
For versions prior to 1.5.2, update to version 1.5.2 or later to resolve the issue. As a temporary workaround, consider disabling the
save global setting AJAX action until a patch is available. Restrict access to the settings modification functionality to minimize the risk of exploitation. Avoid using the affected AJAX endpoint until the issue is resolved.Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Perfect Survey