Vulnerability Details CVE-2023-33668
DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts on shared computers.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 71.5%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-33668
-
cpe:2.3:a:digiexam:digiexam:13.4.3
-
cpe:2.3:a:digiexam:digiexam:13.4.4
-
cpe:2.3:a:digiexam:digiexam:13.5.0
-
cpe:2.3:a:digiexam:digiexam:13.5.2
-
cpe:2.3:a:digiexam:digiexam:13.5.3
-
cpe:2.3:a:digiexam:digiexam:13.5.4
-
cpe:2.3:a:digiexam:digiexam:14.0.0
-
cpe:2.3:a:digiexam:digiexam:14.0.1
-
cpe:2.3:a:digiexam:digiexam:14.0.2