Vulnerabilities > CVE-2021-20113 - Information Exposure Through Discrepancy vulnerability in Tecnick Tcexam

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
tecnick
CWE-203

Summary

An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1. If a password reset request was made for an email address that was not registered with a user then we would be presented with an ‘unknown email’ error. If an email is given that is registered with a user then this error will not appear. A malicious actor could abuse this to enumerate the email addresses of

Vulnerable Configurations

Part Description Count
Application
Tecnick
155

Common Weakness Enumeration (CWE)