CVE-2022-47407: Master-Quiz Project Master-Quiz

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered in the fp_masterquiz (aka Master-Quiz) extension before 2.2.1, and 3.x before 3.5.1, for TYPO3. An attacker can continue the quiz of a different user. In doing so, the attacker can view that user's answers and modify those answers.

Affected products

  • Master-Quiz Project Master-Quiz: before 2.2.1 (fixed in 2.2.1); from 3.0.0, before 3.5.1 (fixed in 3.5.1)

Published 2022-12-14. Last modified 2026-06-17.