The default views in the Quiz module 6.x-4.x before 6.x-4.5 for Drupal allows remote attackers to obtain sensitive quiz results via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://seclists.org/oss-sec/2013/q4/210 | mailing list |
https://drupal.org/node/2123995 | patch vendor advisory |
https://drupal.org/node/2123727 | patch |