Description
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php with a filename beggining with a period will be rendered as text/html. An attacker with access to tce_filemanager.php could upload a malicious javascript payload which would be triggered when another user views the file.
Remediation
References
Related Vulnerabilities
Nginx Out-of-bounds Read Vulnerability (CVE-2023-27728)
Joomla! Core 1.7.x Cross-Site Scripting (1.7.0 - 1.7.3)
WordPress Plugin Limit Attempts by BestWebSoft SQL Injection (1.1.0)
Jenkins Origin Validation Error Vulnerability (CVE-2024-23898)
Oracle Database Server CVE-2015-4873 Vulnerability (CVE-2015-4873)