CVE-2021-20111: XSS
Published Jul 29, 2021
·Updated
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tcefilemanager.php with a filename beggining with a period will be rendered as text/html. An attacker with access to tcefilemanager.php could upload a malicious javascript payload which would be triggered when another user views the file.
Affected Software
1 affected component
Tecnick TCExam<=14.8.1
Event History
Jul 29, 2021
CVE Published
via MITRE·05:57 PM
Data Sourced
via MITRE·05:57 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-20111.
2
What is the severity of CVE-2021-20111?
The severity of CVE-2021-20111 is medium with a CVSS score of 5.4.
3
What is the affected software by CVE-2021-20111?
The affected software is TCExam version up to and including 14.8.1.
4
What is the CWE category of CVE-2021-20111?
The CWE category of CVE-2021-20111 is CWE-79 (Cross-Site Scripting).
5
How can an attacker exploit CVE-2021-20111?
An attacker with access to tce_filemanager.php could upload a malicious JavaScript payload by exploiting CVE-2021-20111.