Description
When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database backup files.
Remediation
References
Related Vulnerabilities
WordPress Plugin weForms-Easy Drag & Drop Contact Form Builder For WordPress CSV Injection (1.4.7)
Drupal Incorrect Authorization Vulnerability (CVE-2017-6377)
WordPress Plugin Yasr-Yet Another Stars Rating Unspecified Vulnerability (0.9.1)
WordPress Plugin Affiliates Manager Multiple Vulnerabilities (2.9.13)