PT-2021-11138 · Projectworlds · Projectworlds Online Examination System
Published
2021-05-24
·
Updated
2021-05-27
·
CVE-2020-25411
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Projectworlds Online Examination System version 1.0
Description:
The issue allows a remote attacker to delete existing users due to a CSRF vulnerability.
Recommendations:
For Projectworlds Online Examination System version 1.0, consider implementing proper CSRF protection mechanisms, such as tokens, to prevent unauthorized actions.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Projectworlds Online Examination System