First published: Sat Jul 07 2018(Updated: )
TCExam before 14.1.2 has XSS via an ff_ or xl_ field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tecnick Tcexam | <14.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13422 is a vulnerability in TCExam before version 14.1.2 that allows for cross-site scripting (XSS) attacks via the ff_ or xl_ field.
CVE-2018-13422 has a severity keyword of 'medium' and a severity value of 6.1 out of 10.
TCExam versions up to but not including 14.1.2 are affected by CVE-2018-13422.
To fix CVE-2018-13422, users should update their TCExam installation to version 14.1.2 or higher.
CVE-2018-13422 is associated with the CWE-79 (Cross-site Scripting) vulnerability.