What the vulnerability does
01Description
Missing Authorization vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.16.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.16.
Explanation of Vulnerability in Simple Terms
Quiz And Survey Master through version 8.1.16 lacks proper authorization checks, allowing unauthenticated attackers to modify quiz or survey data via network requests. No user interaction is required. The vulnerability affects data integrity but not confidentiality or availability. Update to a version newer than 8.1.16.
What an attacker can do
Modify quiz or survey content without authentication.
Potential impact on your site
Quiz and survey data can be altered by anyone on the internet without logging in.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities