Vulnerabilities > Tecnick > High

DATE CVE VULNERABILITY TITLE RISK
2021-07-30 CVE-2021-20114 Forced Browsing vulnerability in Tecnick Tcexam
When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database backup files.
network
low complexity
tecnick CWE-425
7.5
2020-05-07 CVE-2020-5745 Cross-Site Request Forgery (CSRF) vulnerability in Tecnick Tcexam 14.2.2
Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
network
low complexity
tecnick CWE-352
7.4