Sensitive Information Exposure in TCExam by TEConsult
CVE-2021-20113
5.3MEDIUM
What is CVE-2021-20113?
A vulnerability in TCExam allows unauthorized users to perform email enumeration. When a password reset request is submitted for an unregistered email address, the system erroneously confirms that the email is 'unknown', while registered addresses provide no feedback. This behavior can be exploited by malicious actors to identify valid user email addresses, posing a risk of targeted phishing or other attacks.
Affected Version(s)
TCExam 14.8.1