CVE Vulnerabilities

CVE-2022-42197

Direct Request ('Forced Browsing')

Published: Oct 20, 2022 | Modified: May 08, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In Simple Exam Reviewer Management System v1.0 the User List function has improper access control that allows low privileged users to modify user permissions to higher privileges.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

NameVendorStart VersionEnd Version
Simple_exam_reviewer_management_systemSimple_exam_reviewer_management_system_project1.0 (including)1.0 (including)

Potential Mitigations

References