Lucene search

K
cve[email protected]CVE-2023-33668
HistoryJul 12, 2023 - 1:15 p.m.

CVE-2023-33668

2023-07-1213:15:09
CWE-354
web.nvd.nist.gov
14
digiexam
v14.0.2
integrity checks
native modules
pii
account takeover
shared computers

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

46.4%

DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts on shared computers.

Affected configurations

NVD
Node
digiexamdigiexamRange14.0.2
CPENameOperatorVersion
digiexam:digiexamdigiexamle14.0.2

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

46.4%

Related for CVE-2023-33668