Direct static code injection vulnerability in cfgphpquiz/install.php in Walter Beschmout PhpQuiz 1.2 and earlier allows remote attackers to inject arbitrary PHP code in config.inc.php via modified configuration settings.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.125
EPSS Ranking 93.6%