What the vulnerability does
01Description
Missing Authorization vulnerability in Quiz Maker team Quiz Maker.This issue affects Quiz Maker: from n/a through 6.3.9.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Quiz Maker team Quiz Maker.This issue affects Quiz Maker: from n/a through 6.3.9.4.
Explanation of Vulnerability in Simple Terms
Quiz Maker versions up to 6.3.9.4 lack proper authorization checks, allowing an attacker to modify quiz data without authentication. The vulnerability requires specific network conditions to exploit but does not affect data confidentiality or system availability. Site administrators should update to a version newer than 6.3.9.4.
What an attacker can do
Modify quiz content or settings without logging in.
Potential impact on your site
Quiz data could be altered by unauthorized users, affecting quiz integrity and user experience.
Conditions required to exploit
Network access to the site; specific conditions must be met to trigger the vulnerability.
Key dates
External resources
Related vulnerabilities