Missing authorisation in TCExam
Vulnerability Description
When access to the "admin" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it is possible for any user to download protected information like exam answers.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-6554
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Krzysztof Zając (CERT.PL)
Affected Vendor
Tecnick.com
View all reports →