Vulnerabilities (CVE)

Filtered by vendor Tecnick Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-20114 1 Tecnick 1 Tcexam 2022-07-12 5.0 MEDIUM 7.5 HIGH
When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database backup files.
CVE-2020-5745 1 Tecnick 1 Tcexam 2021-07-21 4.3 MEDIUM 7.4 HIGH
Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.