Stored Cross-Site Scripting Vulnerability in TCExam by E-licker
CVE-2021-20112
5.4MEDIUM
What is CVE-2021-20112?
A stored cross-site scripting vulnerability exists in TCExam versions up to 14.8.1. This vulnerability allows valid files uploaded through tce_select_mediafile.php, specifically those whose filenames start with a period, to be treated as text/html. Consequently, an attacker gaining access to this file upload functionality could deliver a malicious JavaScript payload. When another user accesses the affected file, the payload executes, potentially compromising user data and application integrity.
Affected Version(s)
TCExam 14.8.1