Description
Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks via the self-registration feature.
Remediation
References
Related Vulnerabilities
WordPress Plugin InstaWP Connect-1-click WP Staging & Migration Security Bypass (0.1.0.44)
TYPO3 Improper Authentication Vulnerability (CVE-2011-4628)
Serendipity Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1916)
Squid Missing Release of Memory after Effective Lifetime Vulnerability (CVE-2021-28652)