PT-2022-12561 · Xzs-Mysql · Xzs-Mysql

Published

2022-01-25

·

Updated

2022-01-31

·

CVE-2021-46086

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions xzs-mysql versions t3.4.0 and later
Description The issue concerns an insecure permissions vulnerability in the functional method of submitting examination papers in an online examination system. An attacker can exploit this by modifying parameters in the packet using tools like burp suite to potentially destroy real data.
Recommendations For xzs-mysql versions t3.4.0 and later, consider restricting access to the examination paper submission functionality until a proper fix is applied, and review the system's permissions to ensure they are properly secured.

Exploit

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-46086

Affected Products

Xzs-Mysql