First published: Thu May 07 2020(Updated: )
Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks via the self-registration feature.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tecnick Tcexam | =14.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5748 is a vulnerability in TCExam 14.2.2 that allows a remote unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks via the self-registration feature.
CVE-2020-5748 has a severity rating of 6.1 (Medium).
TCExam 14.2.2 is affected by CVE-2020-5748.
A remote unauthenticated attacker can exploit CVE-2020-5748 by conducting persistent cross-site scripting (XSS) attacks via the self-registration feature.
A fix has not been mentioned in the provided information.