PT-2024-35814 · Unknown · Autoquiz Ai Quiz

Mika

·

Published

2024-12-02

·

Updated

2024-12-02

·

CVE-2024-53708

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions AutoQuiz AI Quiz versions n/a through 1.1
Description The issue is related to a missing authorization vulnerability in AutoQuiz AI Quiz, which allows accessing functionality not properly constrained by Access Control Lists (ACLs). This means that certain features or data may be accessible without the necessary permissions, potentially leading to unauthorized access.
Recommendations For versions n/a through 1.1, consider restricting access to sensitive functionality until a proper fix is implemented, ensuring that ACLs are correctly configured to prevent unauthorized access. As a temporary workaround, review and tighten the ACL settings to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-53708

Affected Products

Autoquiz Ai Quiz