CVE-2023-6554: Missing authorisation in TCExam
Published Jan 11, 2024
·Updated
When access to the "admin" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it is possible for any user to download protected information like exam answers.
Affected Software
1 affected component
Tecnick TCExam<15.1.0
Event History
Jan 11, 2024
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-6554?
CVE-2023-6554 is considered a high severity vulnerability due to the potential exposure of sensitive exam answers.
2
How do I fix CVE-2023-6554?
To fix CVE-2023-6554, implement external authorization mechanisms like Apache Basic Auth to protect the 'admin' folder.
3
What information can be exposed in CVE-2023-6554?
CVE-2023-6554 can expose sensitive information such as exam answers if the 'admin' folder is not properly secured.
4
Which software is affected by CVE-2023-6554?
CVE-2023-6554 affects Tecnick Tcexam versions prior to 15.1.0.
5
Who is impacted by CVE-2023-6554?
Any user with access to the unprotected 'admin' folder in affected versions of Tecnick Tcexam is at risk from CVE-2023-6554.