Cross-Site Request Forgery in TCExam by TCE
CVE-2020-5745

7.4HIGH

Key Information:

Vendor

Tecnick

Status
Vendor
CVE Published:
7 May 2020

What is CVE-2020-5745?

A cross-site request forgery (CSRF) vulnerability exists in TCExam version 14.2.2, which allows remote attackers to execute sensitive actions on behalf of legitimate users. By tricking users into clicking a specially crafted link, an attacker can circumvent normal authentication processes, compromising the integrity and confidentiality of the application.

Affected Version(s)

TCExam 14.2.2

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-5745 : Cross-Site Request Forgery in TCExam by TCE