Executive brief
Savsoft Quiz, an open-source platform for managing online exams and assessments, contains a security flaw in its user profile settings. An authenticated user can inject malicious scripts into their profile fields, which will then execute in the browser of any other user or administrator who views that profile. This could lead to unauthorized actions being performed on behalf of other users, including the theft of session cookies or sensitive account information.
Technical details
A persistent cross-site scripting (XSS) vulnerability exists in Savsoft Quiz 5.0 within the 'edit_user' endpoint. The application fails to properly sanitize user-supplied input in profile fields (such as name or login credentials) before storing them in the database and rendering them back to users. An authenticated attacker can submit a payload like '><script>alert(document.cookie);</script>' which is then executed in the context of any user viewing the affected profile. This can be leveraged to steal session tokens or perform unauthorized administrative actions if an admin views the malicious profile. While version 6.0 has been released, users of version 5.0 should ensure they sanitize input or migrate to the newer version.
Affected products
- Savsoft Savsoft Quiz 5.0 and earlier
Timeline
- 2021-05-04: disclosed: Original exploit published on Exploit-DB
- 2022-02-28: other: Version 6.0 released as a major update
- 2026-05-15: advisory: CVE published and NVD record created