PT-2021-11138 · Projectworlds · Projectworlds Online Examination System

Published

2021-05-24

·

Updated

2021-05-27

·

CVE-2020-25411

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Projectworlds Online Examination System version 1.0
Description: The issue allows a remote attacker to delete existing users due to a CSRF vulnerability.
Recommendations: For Projectworlds Online Examination System version 1.0, consider implementing proper CSRF protection mechanisms, such as tokens, to prevent unauthorized actions.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25411

Affected Products

Projectworlds Online Examination System