CVE-2020-5747: XSS
Published May 7, 2020
·Updated
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted test.
Affected Software
1 affected component
Tecnick TCExam=14.2.2
Remediation
Patch Available
Event History
May 7, 2020
CVE Published
via MITRE·04:02 PM
Data Sourced
via MITRE·04:02 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-5747.
2
What is the severity rating of CVE-2020-5747?
CVE-2020-5747 has a severity rating of 5.4, which is considered medium.
3
What is the affected software?
The affected software is TCExam version 14.2.2.
4
What type of vulnerability is CVE-2020-5747?
CVE-2020-5747 is a persistent cross-site scripting (XSS) vulnerability.
5
How can an attacker exploit CVE-2020-5747?
An attacker can exploit CVE-2020-5747 by creating a crafted test to conduct persistent cross-site scripting (XSS) attacks.