{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-6554","assignerOrgId":"4bb8329e-dd38-46c1-aafb-9bf32bcb93c6","state":"PUBLISHED","assignerShortName":"CERT-PL","dateReserved":"2023-12-06T13:46:33.216Z","datePublished":"2024-01-11T15:17:23.523Z","dateUpdated":"2025-06-20T16:34:34.387Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"TCExam","repo":"https://github.com/tecnickcom/tcexam","vendor":"Tecnick.com","versions":[{"lessThan":"15.1.0","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","user":"00000000-0000-4000-9000-000000000000","value":"Krzysztof Zając (CERT.PL)"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<div>When access to the \"admin\" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it is possible for any user to download protected information like exam answers.<br></div><br>"}],"value":"When access to the \"admin\" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it is possible for any user to download protected information like exam answers.\n\n\n\n"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"4bb8329e-dd38-46c1-aafb-9bf32bcb93c6","shortName":"CERT-PL","dateUpdated":"2024-01-11T15:17:23.523Z"},"references":[{"tags":["third-party-advisory"],"url":"https://cert.pl/en/posts/2024/01/CVE-2023-6554/"},{"tags":["third-party-advisory"],"url":"https://cert.pl/posts/2024/01/CVE-2023-6554/"},{"tags":["product"],"url":"https://tcexam.org/"}],"source":{"discovery":"UNKNOWN"},"title":"Missing authorisation in TCExam","x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T08:35:14.736Z"},"title":"CVE Program Container","references":[{"tags":["third-party-advisory","x_transferred"],"url":"https://cert.pl/en/posts/2024/01/CVE-2023-6554/"},{"tags":["third-party-advisory","x_transferred"],"url":"https://cert.pl/posts/2024/01/CVE-2023-6554/"},{"tags":["product","x_transferred"],"url":"https://tcexam.org/"}]},{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":6.5,"attackVector":"NETWORK","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"NONE","privilegesRequired":"LOW","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2024-01-11T17:22:59.733530Z","id":"CVE-2023-6554","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-06-20T16:34:34.387Z"}}]}}