Vulnerability Details CVE-2023-33668
DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts on shared computers.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 75.4%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-33668
-
cpe:2.3:a:digiexam:digiexam:13.4.3
-
cpe:2.3:a:digiexam:digiexam:13.4.4
-
cpe:2.3:a:digiexam:digiexam:13.5.0
-
cpe:2.3:a:digiexam:digiexam:13.5.2
-
cpe:2.3:a:digiexam:digiexam:13.5.3
-
cpe:2.3:a:digiexam:digiexam:13.5.4
-
cpe:2.3:a:digiexam:digiexam:14.0.0
-
cpe:2.3:a:digiexam:digiexam:14.0.1
-
cpe:2.3:a:digiexam:digiexam:14.0.2