CVE-2020-5746: XSS
Published May 7, 2020
·Updated
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted test.
Affected Software
1 affected component
Tecnick TCExam=14.2.2
Remediation
Patch Available
Event History
May 7, 2020
CVE Published
via MITRE·04:08 PM
Data Sourced
via MITRE·04:08 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2020-5746.
2
What is the affected software for this vulnerability?
The affected software for this vulnerability is TCExam version 14.2.2.
3
What type of vulnerability does CVE-2020-5746 have?
CVE-2020-5746 is a persistent cross-site scripting (XSS) vulnerability.
4
How can an attacker exploit this vulnerability?
An attacker can exploit CVE-2020-5746 by creating a crafted test that triggers the XSS attack.
5
What is the severity rating for CVE-2020-5746?
CVE-2020-5746 has a severity rating of medium with a CVSS score of 5.4.