Cross-Site Scripting Vulnerability in TCExam by Instructure
CVE-2020-5751
5.4MEDIUM
What is CVE-2020-5751?
TCExam version 14.2.2 contains a vulnerability due to insufficient output sanitization, which allows a remote, authenticated attacker to execute persistent cross-site scripting (XSS) attacks. By crafting malicious operators, attackers can manipulate the web application to inject arbitrary scripts, potentially compromising user sessions and data.
Affected Version(s)
TCExam 14.2.2
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved