CVE-2026-30707

An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control via the ReviewAnswerDetails ASP.NET PageMethod. Authenticated attackers can bypass client-side restrictions and invoke this method directly to retrieve the full answer key. The provider states that this issue is "Fixed in [02/2026] backend service update."
Configurations

No configuration.

History

24 Mar 2026, 18:16

Type Values Removed Values Added
Summary (en) An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control via the ReviewAnswerDetails ASP.NET PageMethod. Authenticated attackers can bypass client-side restrictions and invoke this method directly to retrieve the full answer key (en) An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control via the ReviewAnswerDetails ASP.NET PageMethod. Authenticated attackers can bypass client-side restrictions and invoke this method directly to retrieve the full answer key. The provider states that this issue is "Fixed in [02/2026] backend service update."

18 Mar 2026, 14:16

Type Values Removed Values Added
CWE CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
Summary
  • (es) Se descubrió un problema en SpeedExam Online Examination System (SaaS) después de la v.FEV2026. Permite un Control de Acceso Roto a través del PageMethod ASP.NET ReviewAnswerDetails. Atacantes autenticados pueden eludir las restricciones del lado del cliente e invocar este método directamente para recuperar la clave de respuestas completa.

17 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-17 20:16

Updated : 2026-05-19 18:08


NVD link : CVE-2026-30707

Mitre link : CVE-2026-30707

CVE.ORG link : CVE-2026-30707


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control