An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control via the ReviewAnswerDetails ASP.NET PageMethod. Authenticated attackers can bypass client-side restrictions and invoke this method directly to retrieve the full answer key. The provider states that this issue is "Fixed in [02/2026] backend service update."
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-03-17 20:16
Updated : 2026-03-24 18:16
NVD link : CVE-2026-30707
Mitre link : CVE-2026-30707
CVE.ORG link : CVE-2026-30707
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control
