CVE Vulnerabilities

CVE-2022-42197

Direct Request ('Forced Browsing')

Published: Oct 20, 2022 | Modified: Aug 08, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In Simple Exam Reviewer Management System v1.0 the User List function has improper access control that allows low privileged users to modify user permissions to higher privileges.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

Name Vendor Start Version End Version
Simple_exam_reviewer_management_system Simple_exam_reviewer_management_system_project 1.0 (including) 1.0 (including)

Potential Mitigations

References