Sensitive Information Exposure in TCExam by TEConsult
CVE-2021-20113

5.3MEDIUM

Key Information:

Vendor

Tecnick

Status
Vendor
CVE Published:
30 July 2021

What is CVE-2021-20113?

A vulnerability in TCExam allows unauthorized users to perform email enumeration. When a password reset request is submitted for an unregistered email address, the system erroneously confirms that the email is 'unknown', while registered addresses provide no feedback. This behavior can be exploited by malicious actors to identify valid user email addresses, posing a risk of targeted phishing or other attacks.

Affected Version(s)

TCExam 14.8.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2021-20113 : Sensitive Information Exposure in TCExam by TEConsult