CVE-2023-27485 MEDIUM

CVE-2023-27485: Insufficient verification of authorisation when accessing subresults in thmmniii/fbs-core

Vendor Thm-Mni-Ii
Product feedbacksystem
Weakness CWE-863 · Incorrect authorization
Published March 7, 2023
Last update February 25, 2025

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

thmmniii/fbs-core is an open source feedback system for students. In versions prior to 1.5.3 when querying `subresults`, it is possible to query `subresults` from other users due to insufficient authorisation. This is only possible for logged-in users and it is not possible to associate the subresults with a specific user. This bug was fixed in commit `f1ae67d8bb2`and released with version 1.5.3. Users are advised to upgrade. There are no known workarounds for this issue.

Key dates

02Disclosure timeline

March 7, 2023 CVE published
February 25, 2025 Record updated