Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Mxsph

#51471de 53,633
4.3CVSS total
Vulnerabilidades · 1
PT-2023-21161
4.3
2023-03-07
Unknown · Thmmniii/Fbs-Core · CVE-2023-27485
**Name of the Vulnerable Software and Affected Versions** thmmniii/fbs-core versions prior to 1.5.3 **Description** thmmniii/fbs-core is an open source feedback system for students. In versions prior to 1.5.3, when querying `subresults`, it is possible to query `subresults` from other users due to insufficient authorisation. This is only possible for logged-in users and it is not possible to associate the subresults with a specific user. **Recommendations** For versions prior to 1.5.3, upgrade to version 1.5.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the `subresults` query for logged-in users until the upgrade is applied.