SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-4500

The Quiz module 6.x-4.x before 6.x-4.5 for Drupal allows remote authenticated users with the "view any quiz results" or "view results for own quiz" permission to delete arbitrary results via the delete option.

MEDIUM 4.9EPSS 1.05%

Does this matter?

Lower severity and a low EPSS score (1.05%). Track it; it rarely justifies an emergency change on its own.

Description

The Quiz module 6.x-4.x before 6.x-4.5 for Drupal allows remote authenticated users with the "view any quiz results" or "view results for own quiz" permission to delete arbitrary results via the delete option.

CVSS 2.0
4.9 MEDIUMAV:N/AC:M/Au:S/C:N/I:P/A:P
EPSS
1.05% probability · 63th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
quiz module project/quiz
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.