Vulnerability Description
DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts on shared computers.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Digiexam | Digiexam | <= 14.0.2 |
Related Weaknesses (CWE)
References
- http://digiexam.comProduct
- https://github.com/lodi-g/CVE-2023-33668ExploitThird Party Advisory
- http://digiexam.comProduct
- https://github.com/lodi-g/CVE-2023-33668ExploitThird Party Advisory
FAQ
What is CVE-2023-33668?
CVE-2023-33668 is a vulnerability with a CVSS score of 9.8 (CRITICAL). DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts on shared computers.
How severe is CVE-2023-33668?
CVE-2023-33668 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-33668?
Check the references section above for vendor advisories and patch information. Affected products include: Digiexam Digiexam.