Description
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted test.
Remediation
References
Related Vulnerabilities
Drupal Improper Authentication Vulnerability (CVE-2019-10911)
Plone CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-4042)
WordPress Plugin eID Easy Cross-Site Scripting (4.6)
Magento Observable Differences in Behavior to Error Inputs Vulnerability (CVE-2020-9690)