Vulnerability Description
xzs-mysql >= t3.4.0 is vulnerable to Insecure Permissions. The front end of this open source system is an online examination system. There is an unsafe vulnerability in the functional method of submitting examination papers. An attacker can use burpuite to modify parameters in the packet to destroy real data.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mindskip | Xzs-Mysql | t3.4.0 |
Related Weaknesses (CWE)
References
- https://github.com/mindskip/xzs-mysql/issues/327ExploitIssue TrackingThird Party Advisory
- https://github.com/mindskip/xzs-mysql/issues/327ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2021-46086?
CVE-2021-46086 is a vulnerability with a CVSS score of 7.5 (HIGH). xzs-mysql >= t3.4.0 is vulnerable to Insecure Permissions. The front end of this open source system is an online examination system. There is an unsafe vulnerability in the functional method of submit...
How severe is CVE-2021-46086?
CVE-2021-46086 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-46086?
Check the references section above for vendor advisories and patch information. Affected products include: Mindskip Xzs-Mysql.