PT-2022-26307 · Unknown · Simple Exam Reviewer Management System

Ciph0X01

·

Published

2022-10-20

·

Updated

2025-05-08

·

CVE-2022-42199

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Simple Exam Reviewer Management System version 1.0
Description The issue concerns a Cross Site Request Forgery (CSRF) vulnerability via the Exam List. This means an attacker could potentially trick a user into performing unintended actions on the system.
Recommendations For Simple Exam Reviewer Management System version 1.0, consider implementing proper CSRF protection mechanisms, such as token-based validation, to prevent unauthorized requests. As a temporary workaround, restrict access to the Exam List feature until a proper fix is applied.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-42199

Affected Products

Simple Exam Reviewer Management System