Advisory:

CSRF in Watu PRO allows unauthenticated attackers to delete quizzes

Vulnerability

Last revised:

An attacker able to convince an admin to visit a link of their choosing is able to delete quizzes.

Current state: Fixed

CVSS Summary

CVSS base scores for this vulnerability
Score 4.3 Medium
Vector Network
Complexity Medium
Authentication None
Confidentiality None
Integrity Partial
Availability None
You can read more about CVSS base scores on Wikipedia or in the CVSS specification.

Proof of concept

Assuming there is a quiz with ID 1, the following link will delete it when visited by a logged-in admin:

http://localhost/wp-admin/admin.php?page=watupro_exams&action=delete&quiz=1

Advisory timeline

  • 2015-08-11: Discovered
  • 2015-08-11: Reported to Author via email
  • 2015-08-11: Author responded
  • 2015-08-26: Author reported fixed in version 4.9.0.8
  • 2015-09-01: Published

Mitigation/further actions

This issue has been discussed with the author, who disagrees that there is an exploitable issue. We maintain that the above proof of concept demonstrates this issue. Nonetheless, the author has told us that they have made changes to address the problem in version 4.9.0.8 of this plugin. We have not verified these changes, so our recommendation is to upgrade to version 4.9.0.8 or later, and ideally conduct your own security assessment of this plugin.