It has been discovered that the extension "Master-Quiz" (fp_masterquiz) is susceptible to Information Disclosure and Broken Access Control.

Problem Description

Insufficient access checks in the extension allow a remote user to continue the quiz of various users, if the quiz has not been finished yet. Thereby, it is also possible for a remote user to view and modify already saved answers of the affected quiz.

Solution

Updated versions 2.2.1 and 3.5.2  are available from the TYPO3 extension manager, packagist and at

https://extensions.typo3.org/extension/download/fp_masterquiz/2.2.1/zip

https://extensions.typo3.org/extension/download/fp_masterquiz/3.5.2/zip

Users of the extension are advised to update the extension as soon as possible.

Credits

Thanks to Kurt Gusbeth for reporting the vulnerabilities and for providing updated versions of the extension.

General Advice

Follow the recommendations that are given in the TYPO3 Security Guide. Please subscribe to the typo3-announce mailing list.