.. / CVE-2021-20114

Exploit for TCExam <= 14.8.1 - Sensitive Information Exposure (CVE-2021-20114)

Description:

When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which includes sensitive database backup files.

Nuclei Template

View the template here CVE-2021-20114.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-20114.yaml
Copy

References:

https://github.com/ARPSyndicate/cvemon
https://nvd.nist.gov/vuln/detail/CVE-2021-20114
https://es-la.tenable.com/security/research/tra-2021-32?tns_redirect=true
https://github.com/ARPSyndicate/kenzer-templates
https://www.tenable.com/security/research/tra-2021-32