CVE-2012-4238: XSS
Cross-site scripting (XSS) vulnerability in admin/code/tceeditanswer.php in TCExam before 11.3.008 allows remote authenticated users with level 5 or greater permissions to inject arbitrary web script or HTML via the questionsubjectid parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4238?
CVE-2012-4238 has a medium severity rating due to its potential for XSS attacks by authenticated users with high-level permissions.
How do I fix CVE-2012-4238?
To fix CVE-2012-4238, upgrade TCExam to version 11.3.008 or later, which patches the XSS vulnerability.
Who is affected by CVE-2012-4238?
CVE-2012-4238 affects TCExam versions prior to 11.3.008 and allows authenticated users with level 5 or greater permissions to exploit the XSS vulnerability.
What kind of attack can CVE-2012-4238 facilitate?
CVE-2012-4238 can facilitate Cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web script or HTML.
Is CVE-2012-4238 a client-side or server-side vulnerability?
CVE-2012-4238 is a server-side vulnerability that affects how a web application handles user input.