First published: Thu May 07 2020(Updated: )
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted group.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tecnick Tcexam | =14.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-5749.
The severity of CVE-2020-5749 is medium with a CVSS score of 5.4.
The affected software version is TCExam 14.2.2.
An attacker can exploit this vulnerability by creating a crafted group and conducting persistent cross-site scripting (XSS) attacks.
Yes, authentication is required to exploit this vulnerability.