PT-2022-9459 · WordPress · The Perfect Survey

Apple502J

·

Published

2022-02-01

·

Updated

2022-02-04

·

CVE-2021-24763

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Perfect Survey WordPress plugin versions prior to 1.5.2
Description The issue is related to the lack of proper authorization and CSRF checks in the save global setting AJAX action. This allows unauthenticated users to edit surveys and modify settings. Additionally, the lack of sanitization and escaping in the settings could lead to a Stored Cross-Site Scripting issue, which would be executed in the context of a user viewing any survey.
Recommendations For versions prior to 1.5.2, update to version 1.5.2 or later to resolve the issue. As a temporary workaround, consider disabling the save global setting AJAX action until a patch is available. Restrict access to the settings modification functionality to minimize the risk of exploitation. Avoid using the affected AJAX endpoint until the issue is resolved.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24763

Affected Products

The Perfect Survey