CVE-2023-33668
CRITICALDigiExam <14.0.2 - Info Disclosure
Title source: llmDescription
DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts on shared computers.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.0088
EPSS Percentile
75.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-354
Status
published
Products (1)
digiexam/digiexam
< 14.0.2
Published
Jul 12, 2023
Tracked Since
Feb 18, 2026