Beijing Yunfan Internet Technology Yunfan Learning Examination System
cpe:2.3:a:kaoshifeng:yunfan_learning_examination_system:*:*:*:*:*:*:*
- 1.9.2
An information disclosure vulnerability has been identified in version 1.9.2 of the Yunfan Learning Examination System by Beijing Yunfan Internet Technology. The issue arises in the Exam Answer Handler component, specifically within the PaperController.java file. The vulnerability allows remote attackers to view answers during the exam process by manipulating input IDs, thereby facilitating cheating.
Exploitation of this vulnerability allows for unauthorized access to exam answers, creating opportunities for cheating.
To reproduce this vulnerability, log into the application and start an exam. Once the exam is in progress, access the results page for the current exam using the exam ID. The correct answers will be displayed, bypassing any exam restrictions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.