CVE-2020-5749: XSS
Published May 7, 2020
·Updated
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted group.
Affected Software
1 affected component
Tecnick TCExam=14.2.2
Remediation
Patch Available
Event History
May 7, 2020
CVE Published
via MITRE·04:15 PM
Data Sourced
via MITRE·04:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-5749.
2
What is the severity of CVE-2020-5749?
The severity of CVE-2020-5749 is medium with a CVSS score of 5.4.
3
What is the affected software version?
The affected software version is TCExam 14.2.2.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by creating a crafted group and conducting persistent cross-site scripting (XSS) attacks.
5
Is authentication required to exploit this vulnerability?
Yes, authentication is required to exploit this vulnerability.