GobyVuls/TCExam/CVE-2021-20114
2021-08-14 18:53:03 +08:00
..
2021-08-14 18:52:38 +08:00

TCExam 14.8.1 Information leakage (CVE-2021-20114)

When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database backup files.

FOFA query rule: app="TCExam"

Demo

TCExam_14_8_1_Information_leakage_CVE_2021_20114