Description
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php with a filename beggining with a period will be rendered as text/html. An attacker with access to tce_filemanager.php could upload a malicious javascript payload which would be triggered when another user views the file.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2013-5775 Vulnerability (CVE-2013-5775)
WordPress Plugin Photo Gallery by Ays-Responsive Image Gallery SQL Injection (4.4.3)
WordPress Plugin WordPress File Upload Cross-Site Scripting (4.3.3)
Jenkins CVE-2023-27902 Vulnerability (CVE-2023-27902)
WordPress Plugin YARPP-Yet Another Related Posts Local File Inclusion (5.30.3)