What the vulnerability does
01Description
Missing Authorization vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.2.
Explanation of Vulnerability in Simple Terms
02Summary
Quiz And Survey Master versions up to 10.3.2 lack proper authorization checks, allowing unauthenticated attackers to modify quiz or survey data over the network. No user interaction is required. The vulnerability does not expose sensitive information or disrupt availability, but attackers can alter quiz content, answers, or settings without permission.
What an attacker can do
03Attacker Capabilities
Modify quiz or survey data without authentication.
Potential impact on your site
04Site Impact
Quiz and survey content can be altered or corrupted by unauthorized parties, affecting data integrity and user trust.
Conditions required to exploit
05Prerequisites
Network access to the affected application; no authentication or user interaction required.
Key dates
06Disclosure timeline
December 9, 2025
CVE published
April 28, 2026
Record updated