Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7gpw-frph-fwrg

Опубликовано: 14 дек. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

TYPO3-EXT-SA-2022-018: Multiple vulnerabilities in extension "Master-Quiz" (fp_masterquiz)

An issue was discovered in the fp_masterquiz (aka Master-Quiz) extension before 2.2.1, and 3.x before 3.5.1, for TYPO3. An attacker can continue the quiz of a different user. In doing so, the attacker can view that user's answers and modify those answers.

Пакеты

Наименование

fixpunkt/fp-masterquiz

composer
Затронутые версииВерсия исправления

>= 3.0.0, < 3.5.2

3.5.2

Наименование

fixpunkt/fp-masterquiz

composer
Затронутые версииВерсия исправления

< 2.2.1

2.2.1

EPSS

Процентиль: 52%
0.00294
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 6.5
nvd
около 3 лет назад

An issue was discovered in the fp_masterquiz (aka Master-Quiz) extension before 2.2.1, and 3.x before 3.5.1, for TYPO3. An attacker can continue the quiz of a different user. In doing so, the attacker can view that user's answers and modify those answers.

EPSS

Процентиль: 52%
0.00294
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284