CVE-2012-4601: SQL Injection
Multiple SQL injection vulnerabilities in Nicola Asuni TCExam before 11.3.009 allow remote authenticated users with level 5 or greater permissions to execute arbitrary SQL commands via the (1) usergroups[] parameter to admin/code/tceedittest.php or (2) subjectid parameter to admin/code/tceshowallquestions.php.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4601?
CVE-2012-4601 is classified as having a medium severity due to the potential for remote authenticated users to execute arbitrary SQL commands.
How do I fix CVE-2012-4601?
To mitigate CVE-2012-4601, upgrade to TCExam version 11.3.009 or later, which addresses the vulnerabilities.
Which versions of TCExam are affected by CVE-2012-4601?
CVE-2012-4601 affects TCExam versions prior to 11.3.009, including various 10.x and 11.0 to 11.2 versions.
Can CVE-2012-4601 be exploited without authentication?
No, exploitation of CVE-2012-4601 requires remote authenticated users with permissions level 5 or greater.
What types of vulnerabilities are described in CVE-2012-4601?
CVE-2012-4601 describes multiple SQL injection vulnerabilities that allow attackers to execute arbitrary SQL commands.