Pearson ProctorCache before 2015.1.17 uses the same hardcoded password across different customers\' installations, which allows remote attackers to modify test metadata or cause a denial of service (test disruption) by leveraging knowledge of this password.