ciph0x01/Simple-Exam-Reviewer-Management-System-CVE

ciph0x01/Simple-Exam-Reviewer-Management-System-CVE

Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
6.5 MEDIUM

In Simple Exam Reviewer Management System v1.0 the User List function has improper access control that allows low privileged users to modify user permissions to higher privileges.

8.8 HIGH

In Simple Exam Reviewer Management System v1.0 the User List function suffers from insecure file upload.

8.8 HIGH

Simple Exam Reviewer Management System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Exam List.

5.4 MEDIUM

Simple Exam Reviewer Management System v1.0 is vulnerable to Stored Cross Site Scripting (XSS) via the Exam List.

7.2 HIGH

Simple Exam Reviewer Management System v1.0 is vulnerable to Insecure file upload.