Pearson ProctorCache before 2015.1.17 uses the same hardcoded password across different customers’ installations, which allows remote attackers to modify test metadata or cause a denial of service (test disruption) by leveraging knowledge of this password.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0972
Reference (s):
- CERT-VN:VU#626420
- URL: http://www.kb.cert.org/vuls/id/626420

