An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control via the ReviewAnswerDetails ASP.NET PageMethod. Authenticated attackers can bypass client-side restrictions and invoke this method directly to retrieve the full answer key. The provider states that this issue is "Fixed in [02/2026] backend service update."
References
Configurations
No configuration.
History
24 Mar 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control via the ReviewAnswerDetails ASP.NET PageMethod. Authenticated attackers can bypass client-side restrictions and invoke this method directly to retrieve the full answer key. The provider states that this issue is "Fixed in [02/2026] backend service update." |
18 Mar 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-284 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.1 |
| Summary |
|
17 Mar 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-17 20:16
Updated : 2026-05-19 18:08
NVD link : CVE-2026-30707
Mitre link : CVE-2026-30707
CVE.ORG link : CVE-2026-30707
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control
