Description
When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database backup files.
Remediation
References
Related Vulnerabilities
WordPress Plugin Tierra's Billboard Manager SQL Injection (1.14)
WordPress Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2020-11027)
RubyGems Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-8324)