Insufficient Output Sanitization in TCExam Affects Remote User Input
CVE-2020-5747

5.4MEDIUM

Key Information:

Vendor

Tecnick

Status
Vendor
CVE Published:
7 May 2020

What is CVE-2020-5747?

An insufficient output sanitization flaw in TCExam 14.2.2 allows a remote attacker with authentication to execute persistent cross-site scripting (XSS) attacks. By crafting carefully designed tests, an attacker can inject malicious scripts into the application, which may be executed when other users view the affected content, potentially leading to the compromise of user data and session hijacking.

Affected Version(s)

TCExam 14.2.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-5747 : Insufficient Output Sanitization in TCExam Affects Remote User Input