Описание
When access to the "admin" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it is possible for any user to download protected information like exam answers.
Ссылки
- Third Party Advisory
- Third Party Advisory
- Product
- Third Party Advisory
- Third Party Advisory
- Product
Уязвимые конфигурации
Конфигурация 1Версия до 15.1.0 (исключая)
cpe:2.3:a:tecnick:tcexam:*:*:*:*:*:*:*:*
EPSS
Процентиль: 40%
0.00184
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-862
CWE-862
Связанные уязвимости
CVSS3: 6.5
github
около 2 лет назад
When access to the "admin" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it is possible for any user to download protected information like exam answers.
EPSS
Процентиль: 40%
0.00184
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-862
CWE-862