Insecure Permissions in Online Examination System by MindSkip
CVE-2021-46086
7.5HIGH
What is CVE-2021-46086?
This vulnerability in the xzs-mysql product presents a significant risk, as it allows attackers to exploit insecure permissions within the system. Specifically, the flaw exists in the method used for submitting examination papers, enabling an attacker to interfere with data integrity. By manipulating parameters in the communication packets with tools like Burp Suite, an attacker can alter or destroy legitimate data submitted through the online examination interface. This can lead to serious implications for academic integrity and data management.