An issue was discovered in the fp_masterquiz (aka Master-Quiz) extension before 2.2.1, and 3.x before 3.5.1, for TYPO3. An attacker can continue the quiz of a different user. In doing so, the attacker can view that user's answers and modify those answers.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| fixpunkt/fp-masterquiz(Packagist) | 3.0.0 | 3.5.2 | N/A |
| fixpunkt/fp-masterquiz(Packagist) | 0 | 2.2.1 | N/A |
CVSS Metrics