Description
Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadata for which they don't have permission.
Remediation
References
Related Vulnerabilities
Nginx CVE-2023-27729 Vulnerability (CVE-2023-27729)
MySQL CVE-2023-22113 Vulnerability (CVE-2023-22113)
Oracle Database Server CVE-2015-2595 Vulnerability (CVE-2015-2595)
Apache Traffic Server Remote DOS Attack (CVE-2021-27737)
WordPress Plugin Newsletter Meenews 'idnews' Parameter Cross-Site Scripting (5.1.0)