CVE-2018-13422: XSS
Published Jul 7, 2018
·Updated
TCExam before 14.1.2 has XSS via an ff or xl field.
Affected Software
1 affected component
Tecnick TCExam<14.1.2
Event History
Jul 7, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-13422?
CVE-2018-13422 is a vulnerability in TCExam before version 14.1.2 that allows for cross-site scripting (XSS) attacks via the ff_ or xl_ field.
2
How severe is CVE-2018-13422?
CVE-2018-13422 has a severity keyword of 'medium' and a severity value of 6.1 out of 10.
3
What software versions are affected by CVE-2018-13422?
TCExam versions up to but not including 14.1.2 are affected by CVE-2018-13422.
4
How can I fix CVE-2018-13422?
To fix CVE-2018-13422, users should update their TCExam installation to version 14.1.2 or higher.
5
What is the Common Weakness Enumeration (CWE) for CVE-2018-13422?
CVE-2018-13422 is associated with the CWE-79 (Cross-site Scripting) vulnerability.