What the vulnerability does
01Description
Missing Authorization vulnerability in Harmonic Design HD Quiz – Save Results Light hd-quiz-save-results-light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HD Quiz – Save Results Light: from n/a through <= 0.5.
Explanation of Vulnerability in Simple Terms
02Summary
HD Quiz – Save Results Light versions 0.5 and earlier lack proper authorization checks on quiz result operations. A logged-in user with low privileges can modify or delete quiz results belonging to other users. The vulnerability requires valid site credentials but no special permissions. Update to a version newer than 0.5 when available.
What an attacker can do
03Attacker Capabilities
Modify or delete quiz results belonging to other users on the site.
Potential impact on your site
04Site Impact
Quiz data integrity is compromised; users' quiz results can be altered or erased by other authenticated users.
Conditions required to exploit
05Prerequisites
Attacker must have a valid user account with low-level site access (e.g., subscriber role).
Key dates
06Disclosure timeline
November 19, 2024
CVE published
May 11, 2026
Record updated