Description
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted test.
Remediation
References
Related Vulnerabilities
WordPress Plugin Age Verification 'redirect_to' Parameter URI Redirection (0.4)
MSSQL information disclosure vulnerability (CVE-2019-0819)
WordPress Plugin Advanced Order Export For WooCommerce CSV Injection (1.5.4)
Joomla! Core Multiple SQL Injection Vulnerabilities (2.5.0 - 3.9.13)
WordPress Plugin Visitor Traffic Real Time Statistics SQL Injection (3.8)